ZeroHour

CVE-2020-7018

CVSS 3.1
8.8 high
EPSS
1%p63
Published
()
Modified
Description

Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, they will be able to view the administrator API credentials. These credentials could allow the developer user to conduct operations with the same permissions of the App Search administrator.

Vendors
elastic
Products
enterprise search
Weakness
CWE-266, CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.