CVE-2019-7619
30.10.2019, 14:15
Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker could send a specially crafted request and determine if a username exists in the Elasticsearch native realm.Enginsight
Vendor | Product | Version |
---|---|---|
elastic | elasticsearch | 6.7.0 ≤ 𝑥 ≤ 6.8.3 |
elastic | elasticsearch | 7.0.0 ≤ 𝑥 ≤ 7.3.2 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References