Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch
Moderate severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Package
Affected versions
>= 6.4.0, <= 6.4.2
Patched versions
6.4.3
Description
Published by the National Vulnerability Database
Dec 20, 2018
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jun 28, 2022
Last updated
Jan 27, 2023
Elasticsearch Security versions 6.4.0 to 6.4.2 contain an error in the way request headers are applied to requests when using the Active Directory, LDAP, Native, or File realms. A request may receive headers intended for another request if the same username is being authenticated concurrently; when used with run as, this can result in the request running as the incorrect user. This could allow a user to access information that they should not have access to.
References