Improper privilege management in elasticsearch
Moderate severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jul 2, 2023
Package
Affected versions
>= 7.0.0, < 7.9.0
< 6.8.12
Patched versions
7.9.0
6.8.12
Description
Published by the National Vulnerability Database
Aug 18, 2020
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Jun 16, 2023
Last updated
Jul 2, 2023
In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security. If a user runs the same query another more privileged user recently ran, the scrolling search can leak fields that should be hidden. This could result in an attacker gaining additional permissions against a restricted index.
References