CVE-2019-7619

All FrameworksElasticsearchCWE-200CVE-2019-7619

CVE-2019-7619

State: PUBLISHED · Published: 2019-10-30 · Updated: 2024-08-04 · Assigner: elastic
Description
Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker could send a specially crafted request and determine if a username exists in the Elasticsearch native realm.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2019/7xxx/CVE-2019-7619.json