Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7530
HistorySep 26, 2018 - 6:29 a.m.

Information Disclosure

2018-09-2606:29:44
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
359

0.001 Low

EPSS

Percentile

34.0%

elasticsearch is vulnerable to information disclosure. The library does not properly filter the settings API, allowing a malicious user can pass a query to the _cluster/settings API to gain access to sensitive configuration information like passwords, tokens or usernames.

CPENameOperatorVersion
serverle6.4.0
serverle5.6.11