CVE-2019-7614

MEDIUM5.9EPSS 0.39%

Concurrent Execution using Shared Resource with Improper Synchronization in Elasticsearch

Published: 5/24/2022Modified: 2/20/2024

Description

A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gain access to response header containing sensitive data from another user.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.9CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

References (3)