VDB
CVE-2019-7614
CVE-2019-7614
PUBLISHED
Es existiert eine Schwachstelle in Elasticsearch. Aufgrund einer Race Condition in den Response-Headern die Elasticsearch auf eine Anfrage zurückgibt, kann ein authentisierter Angreifer unter Umständen Zugriff auf Response-Header von anderen Nutzern erhalten. In der Folge kann er Informationen offenlegen.
EPSS 0.38% · 60.1th percentile
Risk Scores
EPSS Score
0.38%
60.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Enterprise Linux | |
| Open Source | Open Source Elasticsearch <7.2.1 | |
| Open Source | Open Source Elasticsearch <6.8.2 | |
| SolarWinds | SolarWinds Platform <2024.4 |
Exploit Intelligence
- https://www.elastic.co/community/security/ (circl)
- suppressions_cve.xml (github-poc)
- suppressions_cve.xml (github-poc)
- suppressions_cve.xml (github-poc)
- suppressions_cve.xml (github-poc)
- suppressions_cve.xml (github-poc)
- suppressions_cve.xml (github-poc)
Timeline
- Jul 30, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2019/wid-sec-w-2024-3184.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3184 advisory
- https://discuss.elastic.co/t/elastic-stack-6-8-2-and-7-2-1-security-update/192963 advisory
- https://access.redhat.com/errata/RHSA-2019:3024 advisory
- https://support.f5.com/csp/article/K47105354?utm_source=f5support&utm_medium=RSS advisory
- https://access.redhat.com/errata/RHSA-2020:2362 advisory
- https://access.redhat.com/errata/RHSA-2020:2819 advisory
- https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2024-4_release_notes.htm advisory