Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, they will be able to view the administrator API credentials. These credentials could allow the developer user to conduct operations with the same permissions of the App Search administrator.
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Enterprise_search | Elastic | * | 7.9.0 (excluding) |
Elasticsearch | Ubuntu | esm-apps/xenial | * |
Elasticsearch | Ubuntu | trusty | * |
Elasticsearch | Ubuntu | xenial | * |