Security

Volver a Security Alert

Elasticsearch and Liferay Enterprise Search Security Advisory: September 2, 2020

The following issues may affect the functionality of your Liferay DXP and Enterprise Search environment. This notification provides a description of the latest compatibility change and required actions for Liferay Enterprise Search Subscribers.

Deployments which might be impacted

  • Liferay DXP 7.0, 7.1 and 7.2 on Elastic Stack 6.x or 7.x

Vulnerability Information

(As provided by the vendor.)

Elasticsearch field disclosure flaw (ESA-2020-12)

A field disclosure flaw was found in Elasticsearch when running a scrolling search with Field Level Security. If a user runs the same query another more privileged user recently ran, the scrolling search can leak fields that should be hidden. This could result in an attacker gaining additional permissions against a restricted index.

Affected Versions
All versions of Elasticsearch before 7.9.0 and 6.8.12 are affected by this flaw

Solutions and Mitigations
Users should upgrade to Elasticsearch version 7.9.0 or 6.8.12.

CVSSv3: 5.3 - AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

CVE ID: CVE-2020-7019

Additional Information

Liferay's Elasticsearch connectors do not use Field Level Security. Elasticsearch 7.9.x has been added to the compatibility matrix of DXP 7.2*.

Search Engine Compatibility Matrix

Reference the information here for the detailed Elasticsearch compatibility including the compatible connector versions and required patch levels.

Vendor References


*: Elasticsearch 7 requires the "Liferay Connector to Elasticsearch 7" app from Marketplace. The latest version (v3.0.1) requires Service Pack 2+/Fix Pack 5+ patch level.

Elastic, Elasticsearch, and X-Pack are trademarks of Elasticsearch BV, registered in the U.S. and in other countries.

On this page