[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195549

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Privilege escalation vulnerability in Elasticsearch - CVE-2020-7019 (rpm)

ID: oval:org.secpod.oval:def:65223Date: (C)2020-08-24   (M)2023-02-01
Class: VULNERABILITYFamily: unix




The host is installed with Elasticsearch 6.x before 6.8.12 and 7.x before 7.9.0 and is prone to a privilege escalation vulnerability. A flaw is present in the application, which fails to handle hidden fields when query is rerun. Successful exploitation could allow attackers to gain additional permissions against a restricted index.

Platform:
Linux
Product:
elasticsearch
Reference:
CVE-2020-7019
CVE    1
CVE-2020-7019
CPE    2
cpe:/a:elastic:elasticsearch:6.x
cpe:/a:elastic:elasticsearch:7.x

© SecPod Technologies