Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Matt Peel

Researcher fromSilverstripe
#31678of 56,335
8.8Total CVSS
Vulnerabilities · 1
PT-2020-19343
8.8
2020-08-18
Elastic · Vx Search Enterprise · CVE-2020-7018
**Name of the Vulnerable Software and Affected Versions** Elastic Enterprise Search versions prior to 7.9.0 **Description** The issue allows a user with the `developer` role to view the administrator API credentials in the App Search interface. These credentials could enable the developer user to perform operations with the same permissions as the App Search administrator. **Recommendations** For versions prior to 7.9.0, update to version 7.9.0 or later to resolve the issue. As a temporary workaround, consider restricting the `developer` role to minimize the risk of credential exposure.