CVE-2019-7611
HighAdvisory
Published 13 May 2022In the index since 8 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.1
- base score, highest
- EPSS
- 0.021
- 81st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 8
- of 17,781 indexed, latest versions
- Container images
- 7
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Improper Access Control in Elasticsearch
Carried by container images the latest versions of 8 of 17,781 indexed charts deploy, on 7 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| elasticsearchmaven | 1.13.2.0, 2.4.3, 2.4.4, 2.4.6+1 more | 5.6.15 | 7 |
- OSV records
- GHSA-fj32-6v7m-57pg
Charts affected
8 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| siemassist-iot-cybersecurity-monitroting-siem | 0.1.0 | 1 of 3See more | 10,730 |
| graylogt3n | 1.0.0 | 1 of 3See more | 8,063 |
| opendistro-esbeeinventor | 1.15.1 | 1 of 3See more | 5,806 |
| nexusjenkins-x | 0.1.37 | 1 of 1See more | 12,856 |
| elasticsearch2ncsaVerified publisher | 0.2.2 | 1 of 2See more | 4,911 |
| sonatype-nexus3simcube | 1.0.1 | 1 of 2See more | 4,946 |
| sonarqubestakaterVerified publisher | 0.10.3 | 1 of 2See more | 11,841 |
| opendistro-eswitcom-gmbh | 1.13.3 | 1 of 3See more | 5,806 |
Container images carrying it
7 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| amazon/ | 2acfa1dcc5f8 | elasticsearch | 5.6.15 | 2 |
| assistiot/ | ba1d85ec3739 | elasticsearch | 5.6.15 | 1 |
| graylog2/ | 8ff28c66e6c1 | elasticsearch | 5.6.15 | 1 |
| library/ | 41ed3a1a16b6 | elasticsearch | 5.6.15 | 1 |
| library/ | 0ae5169e3d0f | elasticsearch | 5.6.15 | 1 |
| sonatype/ | 586060431b64 | elasticsearch | 5.6.15 | 1 |
| ghcr.io/ | 8caf5289fe73 | elasticsearch | 5.6.15 | 1 |