Low severity3.1NVD Advisory· Published Oct 22, 2020· Updated Jun 17, 2026
CVE-2020-7020
CVE-2020-7020
Description
Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain complex queries. This could result in the search disclosing the existence of documents the attacker should not be able to view. This could result in an attacker gaining additional insight into potentially sensitive indices.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.elasticsearch:elasticsearchMaven | < 6.8.13 | 6.8.13 |
org.elasticsearch:elasticsearchMaven | >= 7.0.0, < 7.9.2 | 7.9.2 |
Affected products
4cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*range: <6.8.13
- (no CPE)range: before 6.8.13 and 7.9.2
- osv-coords2 versions
< 6.8.13+ 1 more
- (no CPE)range: < 6.8.13
- (no CPE)range: < 6.8.13
Patches
Vulnerability mechanics
References
7- discuss.elastic.co/t/elastic-stack-7-9-3-and-6-8-13-security-update/253033nvdRelease NotesVendor AdvisoryWEB
- github.com/advisories/GHSA-g9fw-9x87-rmrjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-7020ghsaADVISORY
- security.netapp.com/advisory/ntap-20201123-0001/nvdThird Party Advisory
- staging-website.elastic.co/community/security/nvdPermissions RequiredVendor Advisory
- security.netapp.com/advisory/ntap-20201123-0001ghsaWEB
- staging-website.elastic.co/community/securityghsaWEB
News mentions
0No linked articles in our index yet.