Document Disclosure Flaw in Elasticsearch by Elastic
CVE-2020-7020

3.1LOW

Key Information:

Vendor
Elastic
Vendor
CVE Published:
22 October 2020

Summary

Elasticsearch versions prior to 6.8.13 and 7.9.2 are vulnerable to a document disclosure issue when utilizing Document or Field Level Security features. Due to inadequate preservation of security permissions during the execution of complex search queries, unauthorized users may inadvertently gain access to information regarding sensitive documents that should remain hidden. This flaw could potentially expose the existence of confidential documents within specified indices, increasing the risk of data breaches.

Affected Version(s)

Elasticsearch before 6.8.13 and 7.9.2

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.