CVE Database
/

CVE-2019-7614

Back to search

CVE-2019-7614

Published: Jul 30, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gain access to response header containing sensitive data from another user.

VendorProductVersions

Elastic

Elasticsearch

affected
before 7.2.1 and 6.8.2

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now