In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security. If a user runs the same query another more privileged user recently ran, the scrolling search can leak fields that should be hidden. This could result in an attacker gaining additional permissions against a restricted index.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NElastic Elasticsearch
APPElastic< 6.8.127.0.0 – 7.9.0 (excl.)
Related vulnerabilities
Elasticsearch: ucieczka z sandboksa Groovy i zdalne wykonanie poleceń
RCE w Elasticsearch przez protokół transportowy (przed wersją 1.6.1)
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers...
Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote...
The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a mo...