Bug 1927480 (CVE-2020-7021) - CVE-2020-7021 elasticsearch: Information disclosure via audit logging with emit_request_body option enabled
Summary: CVE-2020-7021 elasticsearch: Information disclosure via audit logging with em...
Keywords:
Status: CLOSED WONTFIX
Alias: CVE-2020-7021
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1927482 1927481 1927483
Blocks: 1927488
TreeView+ depends on / blocked
 
Reported: 2021-02-10 20:23 UTC by Pedro Sampaio
Modified: 2021-10-28 08:45 UTC (History)
50 users (show)

Fixed In Version: elasticsearch 7.10.0, elasticsearch 6.8.14
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2021-10-28 08:45:04 UTC
Embargoed:


Attachments (Terms of Use)

Description Pedro Sampaio 2021-02-10 20:23:22 UTC
Elasticsearch versions before 7.10.0 and 6.8.14 have an information disclosure issue when audit logging and the emit_request_body option is enabled. The Elasticsearch audit log could contain sensitive information such as password hashes or authentication tokens. This could allow an Elasticsearch administrator to view these details.

References:

https://discuss.elastic.co/t/elastic-stack-7-11-0-and-6-8-14-security-update/263915

Comment 1 Pedro Sampaio 2021-02-10 20:24:34 UTC
Created python-elasticsearch tracking bugs for this issue:

Affects: epel-all [bug 1927482]
Affects: fedora-all [bug 1927483]
Affects: openstack-rdo [bug 1927481]

Comment 3 Przemyslaw Roguski 2021-02-15 18:08:33 UTC
The audit logging requires xpack security audit plugin and GOLD/PLATINUM/ENTERPRISE subscription. 
So the vulnerable component is not available in the opensource version.


Note You need to log in before you can comment on or make changes to this bug.