CVE-2020-7019
Improper privilege management in elasticsearch
6.5
MEDIUM
CVSS 3.1
EPSS 1.2%
描述
In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security. If a user runs the same query another more privileged user recently ran, the scrolling search can leak fields that should be hidden. This could result in an attacker gaining additional permissions against a restricted index.
如何修補 CVE-2020-7019
要修補 CVE-2020-7019,請將受影響套件升級到下列已修補版本。
- —升級至 6.8.12 或更新版本
- —升級至 7.9.0 或更新版本
CVE-2020-7019 正在被利用嗎?
低 — EPSS 為 1.2%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 6.8.12, >= 7.0.0, < 7.9.0
- >= 7.0.0, < 7.9.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |