elastic elasticsearch CVE-2019-7611 is a vulnerability in Elasticsearch
Published on March 25, 2019

A permission issue was found in Elasticsearch versions before 5.6.15 and 6.6.1 when Field Level Security and Document Level Security are disabled and the _aliases, _shrink, or _split endpoints are used . If the elasticsearch.yml file has xpack.security.dls_fls.enabled set to false, certain permission checks are skipped when users perform one of the actions mentioned above, to make existing data available under a new index/alias name. This could result in an attacker gaining additional permissions against a restricted index.

NVD

Weakness Type

What is an Authorization Vulnerability?

The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVE-2019-7611 has been classified to as an Authorization vulnerability or weakness.


Products Associated with CVE-2019-7611

Want to know whenever a new CVE is published for Elasticsearch? stack.watch will email you.

 

Affected Versions

Elasticsearch Version before 5.6.15 and 6.6.1 is affected by CVE-2019-7611

Exploit Probability

EPSS
0.71%
Percentile
72.02%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.