Skip to content

Commit facdf64

Browse files
committed
Mention CVE-2020-7021 under 6.8.14 release notes
1 parent e513dbe commit facdf64

File tree

1 file changed

+13
-0
lines changed

1 file changed

+13
-0
lines changed

docs/reference/release-notes/6.8.asciidoc

+13
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,19 @@
33

44
Also see <<breaking-changes-6.8,Breaking changes in 6.8>>.
55

6+
[discrete]
7+
[[security-updates-6.8.14]]
8+
=== Security updates
9+
10+
* {es} versions before 7.10.0 and 6.8.14 have an information
11+
disclosure issue when audit logging and the `emit_request_body` option are
12+
enabled. The {es} audit log could contain sensitive information,
13+
such as password hashes or authentication tokens. This could allow an
14+
{es} administrator to view these details.
15+
You must upgrade to {es} version 6.8.14 to obtain the fix.
16+
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7021[CVE-2020-7021]
17+
18+
619
[[bug-6.8.14]]
720
[float]
821
=== Bug fixes

0 commit comments

Comments
 (0)