First published: Tue Aug 18 2020(Updated: )
Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, they will be able to view the administrator API credentials. These credentials could allow the developer user to conduct operations with the same permissions of the App Search administrator.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic Enterprise Search | <7.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-7018.
The severity of CVE-2020-7018 is high with a severity value of 8.8.
Elastic Enterprise Search versions up to and excluding 7.9.0 are affected by CVE-2020-7018.
If a user is given the 'developer' role, they can view the administrator API credentials and potentially conduct operations with the same permissions.
Yes, a security update is available for Elastic Enterprise Search in version 7.9.0.