-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.elasticsearch:elasticsearch | maven | >= 6.7.0, <= 6.8.3 | 6.8.4 |
| org.elasticsearch:elasticsearch | maven | >= 7.0.0, <= 7.3.2 | 7.4.0 |
The vulnerability stems from the API Key service's username validation logic. When creating API keys, the endpoint returned distinguishable error messages between invalid credentials and non-existent users. This allowed attackers to enumerate valid usernames via error response analysis. The function handling API key creation (createApiKey) in the security module's ApiKeyService class is directly responsible for this validation, making it the vulnerable component. The lack of generic error messages in affected versions enabled this information leak.
Ongoing coverage of React2Shell