Candidate: CVE-2019-7614 PublicDate: 2019-07-30 22:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7614 Description: A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gain access to response header containing sensitive data from another user. Ubuntu-Description: Notes: sbeattie| vulnerability is in elasticsearch X-pack's Security module, which was added to elasticsearch in the 6.3/7.0 timeframe. Mitigation: Bugs: https://github.com/elastic/elasticsearch/pull/43436 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N [5.9 MEDIUM] Patches_elasticsearch: upstream: https://github.com/elastic/elasticsearch/commit/3b41416c6c3245c93c502324eebee35081605525 upstream_elasticsearch: needs-triage precise/esm_elasticsearch: DNE trusty_elasticsearch: DNE trusty/esm_elasticsearch: DNE xenial_elasticsearch: not-affected (code not present) bionic_elasticsearch: DNE focal_elasticsearch: DNE groovy_elasticsearch: DNE devel_elasticsearch: DNE