Back

MEDIUM

elasticsearch: Race condition in response headers on systems with multiple submitting requests

Published Jul 30, 2019

Description

A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gain access to response header containing sensitive data from another user.

Affected products

Remediation

Red Hat mitigation

There is no mitigation for this issue, the flaw can only be resolved by applying updates.

Metrics

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner elastic
Published Jul 30, 2019
Updated Aug 4, 2024
Reserved Feb 7, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jul 31, 2019
GHSA-JQM6-M3J3-8GG9