Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20937
HistoryJul 31, 2019 - 8:45 a.m.

Information Leakage

2019-07-3108:45:23
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
853

0.002 Low

EPSS

Percentile

53.8%

Elasticsearch is vulnerable to information leakage. An attacker can gain access to the other user’s sensitive information in the response header if multiple users submitting requests, causing a race condition in response headers.

CPENameOperatorVersion
serverle7.2.0
serverle6.8.1