ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-7021”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-7021
Published
2021-02-10
CVSS:
4.9
ShadowTrackr CVSS:
5.0
Summary:
Elasticsearch versions before 7.10.0 and 6.8.14 have an information disclosure issue when audit logging and the emit_request_body option is enabled. The Elasticsearch audit log could contain sensitive information such as password hashes or authentication tokens. This could allow an Elasticsearch administrator to view these details.