CVE-2020-7019 Vulnerability Details

  /     /     /  

CVE-2020-7019 Metadata Quick Info

CVE Published: 18/08/2020 | CVE Updated: 04/08/2024 | CVE Year: 2020
Source: elastic | Vendor: Elastic | Product: Elasticsearch
Status : PUBLISHED

CVE-2020-7019 Description

In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security. If a user runs the same query another more privileged user recently ran, the scrolling search can leak fields that should be hidden. This could result in an attacker gaining additional permissions against a restricted index.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-270
CWE Name: CWE-270: Privilege Context Switching Error
Source: Elastic

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).