Oval Definition:oval:org.opensuse.security:def:20197611
Revision Date:2022-05-22Version:1
Title:CVE-2019-7611
Description:

A permission issue was found in Elasticsearch versions before 5.6.15 and 6.6.1 when Field Level Security and Document Level Security are disabled and the _aliases, _shrink, or _split endpoints are used . If the elasticsearch.yml file has xpack.security.dls_fls.enabled set to false, certain permission checks are skipped when users perform one of the actions mentioned above, to make existing data available under a new index/alias name. This could result in an attacker gaining additional permissions against a restricted index.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2019-7611
SUSE CVE-2019-7611
Platform(s):SUSE OpenStack Cloud 7
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND elasticsearch is not affected
  • Definition Synopsis
  • Release Information
  • SUSE OpenStack Cloud 8 is installed
  • OR SUSE OpenStack Cloud Crowbar 8 is installed
  • AND elasticsearch is not affected
  • BACK