Lucene search

K
ubuntucveUbuntu.comUB:CVE-2020-7020
HistoryOct 22, 2020 - 12:00 a.m.

CVE-2020-7020

2020-10-2200:00:00
ubuntu.com
ubuntu.com
19

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

3.1 Low

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

0.001 Low

EPSS

Percentile

30.0%

Elasticsearch versions before 6.8.13 and 7.9.2 contain a document
disclosure flaw when Document or Field Level Security is used. Search
queries do not properly preserve security permissions when executing
certain complex queries. This could result in the search disclosing the
existence of documents the attacker should not be able to view. This could
result in an attacker gaining additional insight into potentially sensitive
indices.

OSVersionArchitecturePackageVersionFilename
ubuntu16.04noarchelasticsearch< anyUNKNOWN

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

3.1 Low

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

0.001 Low

EPSS

Percentile

30.0%