CVE-2020-7019
MediumAdvisory
Published 24 May 2022In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.5
- base score, highest
- EPSS
- 0.012
- 67th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 16
- of 17,781 indexed, latest versions
- Container images
- 14
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Improper privilege management in elasticsearch
Carried by container images the latest versions of 16 of 17,781 indexed charts deploy, on 14 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| elasticsearchmaven | 1.13.2.0, 2.4.3, 2.4.4, 2.4.6+8 more | 6.8.12, 7.9.0 | 14 |
- OSV records
- GHSA-c77j-p484-h84m
- Also known as
- BIT-elasticsearch-2020-7019
Charts affected
16 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| skywalkingkubesphere-testVerified publisher | 3.1.0 | 1 of 4See more | 18,042 |
| siemassist-iot-cybersecurity-monitroting-siem | 0.1.0 | 1 of 3See more | 10,730 |
| elasticsearch-dataempathyco | 0.2.0 | 1 of 2See more | 3,703 |
| elasticsearch-masterempathyco | 0.3.0 | 1 of 2See more | 3,703 |
| graylogt3n | 1.0.0 | 1 of 3See more | 8,063 |
| opendistro-esbeeinventor | 1.15.1 | 1 of 3See more | 5,806 |
| apache-ranger-admindata-platform-stableVerified publisher | 0.2.0 | 1 of 2See more | 8,245 |
| ibm-business-automation-insights-devibm-charts | 3.2.0 | 1 of 6See more | 39,349 |
| nexusjenkins-x | 0.1.37 | 1 of 1See more | 12,856 |
| tampkubebb | 5.6.0 | 1 of 2See more | 4,664 |
| opendistro-eslsst-sqre | 1.4.1 | 1 of 3See more | 7,929 |
| elasticsearch2ncsaVerified publisher | 0.2.2 | 1 of 2See more | 4,911 |
| sonatype-nexus3simcube | 1.0.1 | 1 of 2See more | 4,946 |
| sonarqubestakaterVerified publisher | 0.10.3 | 1 of 2See more | 11,841 |
| sonarqubewebencryptor | 6.7.3 | 1 of 3See more | 5,460 |
| opendistro-eswitcom-gmbh | 1.13.3 | 1 of 3See more | 5,806 |
Container images carrying it
14 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| amazon/ | 2acfa1dcc5f8 | elasticsearch | 6.8.12 | 2 |
| empathyco/ | bcf4365ee7ec | elasticsearch | 6.8.12 | 2 |
| amazon/ | 6df71eb04639 | elasticsearch | 7.9.0 | 1 |
| apache/ | 641237e0299b | elasticsearch | 7.9.0 | 1 |
| assistiot/ | ba1d85ec3739 | elasticsearch | 6.8.12 | 1 |
| egdsandaru/ | 681baa1926f4 | elasticsearch | 7.9.0 | 1 |
| graylog2/ | 8ff28c66e6c1 | elasticsearch | 6.8.12 | 1 |
| ibmcom/ | 5441dba2fa00 | elasticsearch | 6.8.12 | 1 |
| kubebb/ | 4d062f20309c | elasticsearch | 7.9.0 | 1 |
| library/ | 41ed3a1a16b6 | elasticsearch | 6.8.12 | 1 |
| library/ | 0ae5169e3d0f | elasticsearch | 6.8.12 | 1 |
| library/ | a246bc64207e | elasticsearch | 6.8.12 | 1 |
| sonatype/ | 586060431b64 | elasticsearch | 6.8.12 | 1 |
| ghcr.io/ | 8caf5289fe73 | elasticsearch | 6.8.12 | 1 |