Improper access control in Elasticsearch - CVE-2019-7611
Published: March 27, 2019
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to sensitive information.
The vulnerability exists due to improper access restrictions when Field Level Security and Document Level Security are disabled and the _aliases, _shrink, or _split endpoints are used, which means that elasticsearch.yml file has xpack.security.dls_fls.enabled set to false. A remote authenticated attacker can make API calls to the _aliases, _shrink, or _split endpoints and make existing data available under a new index/alias name.
Affected software
Arch Linux
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Junos Space Security Director
How to mitigate CVE-2019-7611
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.7.0
Junos Space Security Director - update to 24.1R3