Meet Corgea at Black Hat, BSides Las Vegas & DEF CON
MEDIUM 5.9 Maven

Concurrent Execution using Shared Resource with Improper Synchronization in Elasticsearch

GHSA-jqm6-m3j3-8gg9 · CVE-2019-7614

Published · Modified

Description

A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gain access to response header containing sensitive data from another user.

Ready to move

Start Securing

Free, no credit card | First findings in minutes