CVE-2020-7018

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
18/08/2020
Last modified:
26/08/2020

Description

Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, they will be able to view the administrator API credentials. These credentials could allow the developer user to conduct operations with the same permissions of the App Search administrator.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:elastic:enterprise_search:*:*:*:*:*:*:*:* 7.9.0 (excluding)