← Back to CVE List

CVE-2020-7021

Published: 2021-02-10T19:15Z
Last Modified: 2024-11-21T05:36Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Elasticsearch versions before 7.10.0 and 6.8.14 have an information disclosure issue when audit logging and the emit_request_body option is enabled. The Elasticsearch audit log could contain sensitive information such as password hashes or authentication tokens. This could allow an Elasticsearch administrator to view these details. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt