Elasticsearch是一个基于Lucene库的搜索引擎。 Elasticsearch 7.2.1之前版本和6.8.2之前版本中存在竞争条件问题漏洞。攻击者可利用该漏洞获取含有其他用户敏感信息的响应头的访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Elastic | Elasticsearch | before 7.2.1 and 6.8.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2019-7615 | Elasticsearch Elastic APM agent for Ruby 信任管理问题漏洞 | |
| CVE-2019-7616 | Elasticsearch Kibana 代码问题漏洞 |
No comments yet