← Back to CVE List

CVE-2020-7018

Published: 2020-08-18T17:15Z
Last Modified: 2024-11-21T05:36Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, they will be able to view the administrator API credentials. These credentials could allow the developer user to conduct operations with the same permissions of the App Search administrator. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt