StackRadar

CVE-2020-7019

Medium

Advisory

Published 24 May 2022In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.012
67th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
16
of 17,781 indexed, latest versions
Container images
14
deployed by those charts
Fix available
1 of 1
affected package

Improper privilege management in elasticsearch

Carried by container images the latest versions of 16 of 17,781 indexed charts deploy, on 14 images.

Affected packageAffected versionsFixed inImages
elasticsearchmaven1.13.2.0, 2.4.3, 2.4.4, 2.4.6+8 more6.8.12, 7.9.014
OSV records
GHSA-c77j-p484-h84m
Also known as
BIT-elasticsearch-2020-7019

Charts affected

16 by stars
ChartLatestAffected imagesRadar Score
skywalkingkubesphere-testVerified publisher3.1.01 of 4See more

skywalking kubesphere-test 3.1.0

1 of the 4 container images this version deploys carry CVE-2020-7019.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.1.0-es7641237e0299b
elasticsearch@7.0.0
7.9.0

Open the chart page →

18,042
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2020-7019.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
elasticsearch@1.13.2.0
6.8.12

Open the chart page →

10,730
elasticsearch-dataempathyco0.2.01 of 2See more

elasticsearch-data empathyco 0.2.0

1 of the 2 container images this version deploys carry CVE-2020-7019.

Container imageDigestPackageFixed in
empathyco/elasticsearch:6.6.2-memlockbcf4365ee7ec
elasticsearch@6.6.2
6.8.12

Open the chart page →

3,703
elasticsearch-masterempathyco0.3.01 of 2See more

elasticsearch-master empathyco 0.3.0

1 of the 2 container images this version deploys carry CVE-2020-7019.

Container imageDigestPackageFixed in
empathyco/elasticsearch:6.6.2-memlockbcf4365ee7ec
elasticsearch@6.6.2
6.8.12

Open the chart page →

3,703
graylogt3n1.0.01 of 3See more

graylog t3n 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-7019.

Container imageDigestPackageFixed in
graylog2/server:2.4.3-38ff28c66e6c1
elasticsearch@2.4.4
6.8.12

Open the chart page →

8,063
opendistro-esbeeinventor1.15.11 of 3See more

opendistro-es beeinventor 1.15.1

1 of the 3 container images this version deploys carry CVE-2020-7019.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
elasticsearch@1.13.2.0
6.8.12

Open the chart page →

5,806
apache-ranger-admindata-platform-stableVerified publisher0.2.01 of 2See more

apache-ranger-admin data-platform-stable 0.2.0

1 of the 2 container images this version deploys carry CVE-2020-7019.

Container imageDigestPackageFixed in
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
elasticsearch@7.6.0
7.9.0

Open the chart page →

8,245
ibm-business-automation-insights-devibm-charts3.2.01 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

1 of the 6 container images this version deploys carry CVE-2020-7019.

Container imageDigestPackageFixed in
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
elasticsearch@6.7.1
6.8.12

Open the chart page →

39,349
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2020-7019.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
elasticsearch@2.4.3
6.8.12

Open the chart page →

12,856
tampkubebb5.6.01 of 2See more

tamp kubebb 5.6.0

1 of the 2 container images this version deploys carry CVE-2020-7019.

Container imageDigestPackageFixed in
kubebb/gateway-api:v5.6.04d062f20309c
elasticsearch@7.8.1
7.9.0

Open the chart page →

4,664
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2020-7019.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
elasticsearch@7.4.2
7.9.0

Open the chart page →

7,929
elasticsearch2ncsaVerified publisher0.2.21 of 2See more

elasticsearch2 ncsa 0.2.2

1 of the 2 container images this version deploys carry CVE-2020-7019.

Container imageDigestPackageFixed in
library/elasticsearch:2.4.641ed3a1a16b6
elasticsearch@2.4.6
6.8.12

Open the chart page →

4,911
sonatype-nexus3simcube1.0.11 of 2See more

sonatype-nexus3 simcube 1.0.1

1 of the 2 container images this version deploys carry CVE-2020-7019.

Container imageDigestPackageFixed in
sonatype/nexus3:3.58.1586060431b64
elasticsearch@2.4.3
6.8.12

Open the chart page →

4,946
sonarqubestakaterVerified publisher0.10.31 of 2See more

sonarqube stakater 0.10.3

1 of the 2 container images this version deploys carry CVE-2020-7019.

Container imageDigestPackageFixed in
library/sonarqube:6.7.6-community0ae5169e3d0f
elasticsearch@5.6.3
6.8.12

Open the chart page →

11,841
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2020-7019.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
elasticsearch@6.8.4
6.8.12

Open the chart page →

5,460
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2020-7019.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
elasticsearch@1.13.2.0
6.8.12

Open the chart page →

5,806

Container images carrying it

14 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
elasticsearch@1.13.2.0
6.8.12
2
empathyco/elasticsearch:6.6.2-memlockbcf4365ee7ec
elasticsearch@6.6.2
6.8.12
2
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
elasticsearch@7.4.2
7.9.0
1
apache/skywalking-oap-server:8.1.0-es7641237e0299b
elasticsearch@7.0.0
7.9.0
1
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
elasticsearch@1.13.2.0
6.8.12
1
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
elasticsearch@7.6.0
7.9.0
1
graylog2/server:2.4.3-38ff28c66e6c1
elasticsearch@2.4.4
6.8.12
1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
elasticsearch@6.7.1
6.8.12
1
kubebb/gateway-api:v5.6.04d062f20309c
elasticsearch@7.8.1
7.9.0
1
library/elasticsearch:2.4.641ed3a1a16b6
elasticsearch@2.4.6
6.8.12
1
library/sonarqube:6.7.6-community0ae5169e3d0f
elasticsearch@5.6.3
6.8.12
1
library/sonarqube:8.2-communitya246bc64207e
elasticsearch@6.8.4
6.8.12
1
sonatype/nexus3:3.58.1586060431b64
elasticsearch@2.4.3
6.8.12
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
elasticsearch@2.4.3
6.8.12
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.