- CVE ID
- CVE-2020-7021
- CVE Description
- Elasticsearch versions before 7.10.0 and 6.8.14 have an information disclosure issue when audit logging and the emit_request_body option is enabled. The Elasticsearch audit log could contain sensitive information such as password hashes or authentication tokens. This could allow an Elasticsearch administrator to view these details.
- Published
- May 18, 2026
- CVSS Score & Severity
4.9Medium
- CVSS Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS Score
- 0.478%
- KEV Status
Not in KEV Catalog: No known exploits
- Source
- National Vulnerability Database