CVE-2019-7619
30.10.2019, 14:15
Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker could send a specially crafted request and determine if a username exists in the Elasticsearch native realm.Enginsight
| Vendor | Product | Version |
|---|---|---|
| elastic | elasticsearch | 6.7.0 ≤ 𝑥 ≤ 6.8.3 |
| elastic | elasticsearch | 7.0.0 ≤ 𝑥 ≤ 7.3.2 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References