elasticsearch: Improper permission issue when attaching a new name to an index
Published Mar 25, 2019
8.1
HIGHCVSS 3.1
EPSS 2.15%
Description
A permission issue was found in Elasticsearch versions before 5.6.15 and 6.6.1 when Field Level Security and Document Level Security are disabled and the _aliases, _shrink, or _split endpoints are used . If the elasticsearch.yml file has xpack.security.dls_fls.enabled set to false, certain permission checks are skipped when users perform one of the actions mentioned above, to make existing data available under a new index/alias name. This could result in an attacker gaining additional permissions against a restricted index.
Affected products
-
- Version before 5.6.15 and 6.6.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Elastic | Elasticsearch | n/a |
|
- < 5.6.15
- ≥ 6.0.0 · < 6.6.1
No data.
Red Hat Decision Manager 7
elasticsearch
Fixed · RHSA-2020:0899
Red Hat Process Automation 7
elasticsearch
Fixed · RHSA-2020:0895
Red Hat Fuse 7
elasticsearch
Not affected
Red Hat JBoss Fuse 6
elasticsearch
Out of support scope
Red Hat OpenShift Container Platform 3.10
elasticsearch
Will not fix
Red Hat OpenShift Container Platform 3.11
openshift3/ose-logging-elasticsearch5
Will not fix
Red Hat OpenShift Container Platform 3.2
elasticsearch
Out of support scope
Red Hat OpenShift Container Platform 3.3
elasticsearch
Out of support scope
Red Hat OpenShift Container Platform 3.4
elasticsearch
Out of support scope
Red Hat OpenShift Container Platform 3.5
elasticsearch
Out of support scope
Red Hat OpenShift Container Platform 3.6
elasticsearch
Out of support scope
Red Hat OpenShift Container Platform 3.7
elasticsearch
Out of support scope
Red Hat OpenShift Container Platform 3.9
elasticsearch
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/ose-logging-elasticsearch5
Will not fix
Red Hat OpenShift Enterprise 3.1
elasticsearch
Out of support scope
Red Hat OpenStack Platform 8 (Liberty) Operational Tools
elasticsearch
Not affected
Red Hat OpenStack Platform 9 (Mitaka) Operational Tools
elasticsearch
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Decision Manager 7 | elasticsearch | Fixed | RHSA-2020:0899 |
| Red Hat Process Automation 7 | elasticsearch | Fixed | RHSA-2020:0895 |
| Red Hat Fuse 7 | elasticsearch | Not affected | n/a |
| Red Hat JBoss Fuse 6 | elasticsearch | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.10 | elasticsearch | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.11 | openshift3/ose-logging-elasticsearch5 | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.2 | elasticsearch | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.3 | elasticsearch | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.4 | elasticsearch | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.5 | elasticsearch | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.6 | elasticsearch | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.7 | elasticsearch | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.9 | elasticsearch | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-logging-elasticsearch5 | Will not fix | n/a |
| Red Hat OpenShift Enterprise 3.1 | elasticsearch | Out of support scope | n/a |
| Red Hat OpenStack Platform 8 (Liberty) Operational Tools | elasticsearch | Not affected | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) Operational Tools | elasticsearch | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat OpenStack Platform 8.0/9.0 Operational Tools Kibana/Elasticsearch versions do not include nor support X-Pack (8/9 versions must use the optional Shield, also not packaged); not affected. OpenShift Container Platform (OCP) does not include X-Pack with Elasticsearch, which prevents this vulnerability from being exploited. However, versions of Elasticsearch shipped in OCP do contain the vulnerable code which could allow this vulnerability to be exploited if X-Pack was installed.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 2.15% (0.02149) | 81.47th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.15% (0.02149) | 79.67th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.24% (0.00244) | 64.91th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.24% (0.00244) | 63.53th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.24% (0.00244) | 60.55th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.89% (0.00885) | 24.24th | v2 (v2022.01.01) |
| Feb 4, 2022 | 9.03% (0.09029) | 86.86th | v2 (v2022.01.01) |
| Feb 3, 2022 | 2.74% (0.02742) | 63.06th | v5 (v2026.06.15) |
| Jan 6, 2022 | 2.74% (0.02742) | 62.72th | v1 |
| Sep 1, 2021 | 0.62% (0.00624) | 45.04th | v1 |
| Apr 14, 2021 | 0.62% (0.00624) | 0.00th | v1 |
References (7)
- https://access.redhat.com/security/cve/CVE-2019-7611 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1696034 Issue Tracking
- https://discuss.elastic.co/t/elastic-stack-6-6-1-and-5-6-15-security-update/169077 x_refsource_MISCVendor Advisory
- https://github.com/advisories/GHSA-fj32-6v7m-57pg Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-7611
- https://www.cve.org/CVERecord?id=CVE-2019-7611
- https://www.elastic.co/community/security x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-7611 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1696034 | Issue Tracking | |
| https://discuss.elastic.co/t/elastic-stack-6-6-1-and-5-6-15-security-update/169077 | x_refsource_MISCVendor Advisory | |
| https://github.com/advisories/GHSA-fj32-6v7m-57pg | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-7611 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-7611 | ||
| https://www.elastic.co/community/security | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.