Inclusion of Sensitive Information in Log Files in Elasticsearch - CVE-2020-7021

 

Inclusion of Sensitive Information in Log Files in Elasticsearch - CVE-2020-7021

Published: February 11, 2021 / Updated: February 11, 2021


Vulnerability identifier: #VU50604
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-7021
CWE-ID: CWE-532
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote administrator to gain access to sensitive information.

The vulnerability exists due to software stores sensitive information into log files, when audit logging and the emit_request_body option is enabled. The Elasticsearch administrator can view the audit log and obtain password hashes or authentication tokens in clear text.


Affected software

Elasticsearch
Junos Space Security Director

How to mitigate CVE-2020-7021

Install updates from vendor's website.

Elasticsearch - addressed in versions 6.8.14, 7.10.0
Junos Space Security Director - update to 24.1R3

External References

Related Security Bulletins