Inclusion of Sensitive Information in Log Files in Elasticsearch - CVE-2020-7021
Published: February 11, 2021 / Updated: February 11, 2021
Vulnerability details
The vulnerability allows a remote administrator to gain access to sensitive information.
The vulnerability exists due to software stores sensitive information into log files, when audit logging and the emit_request_body option is enabled. The Elasticsearch administrator can view the audit log and obtain password hashes or authentication tokens in clear text.
Affected software
Junos Space Security Director
How to mitigate CVE-2020-7021
Junos Space Security Director - update to 24.1R3