Description
A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gain access to response header containing sensitive data from another user.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4417 | A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gain access to response header containing sensitive data from another user. |
Github GHSA |
GHSA-jqm6-m3j3-8gg9 | Concurrent Execution using Shared Resource with Improper Synchronization in Elasticsearch |
References
History
No history.
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2024-08-04T20:54:28.068Z
Reserved: 2019-02-07T00:00:00.000Z
Link: CVE-2019-7614
No data.
Status : Modified
Published: 2019-07-30T22:15:12.443
Modified: 2024-11-21T04:48:24.303
Link: CVE-2019-7614
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA