Lucene search

K
cvelistElasticCVELIST:CVE-2020-7018
HistoryAug 18, 2020 - 4:40 p.m.

CVE-2020-7018

2020-08-1816:40:14
CWE-266
elastic
www.cve.org
5
elastic
enterprise search
credential exposure
app search
administrator api

AI Score

8.5

Confidence

High

EPSS

0.001

Percentile

42.8%

Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, they will be able to view the administrator API credentials. These credentials could allow the developer user to conduct operations with the same permissions of the App Search administrator.

CNA Affected

[
  {
    "product": "Elastic Enterprise Search",
    "vendor": "Elastic",
    "versions": [
      {
        "status": "affected",
        "version": "before 7.9.0"
      }
    ]
  }
]

AI Score

8.5

Confidence

High

EPSS

0.001

Percentile

42.8%

Related for CVELIST:CVE-2020-7018