{"id":"CVE-2019-7619","aliases":["GHSA-hxp8-r9g3-grfr"],"url":"https://o3.security/vulnerability/CVE-2019-7619","summary":"Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch","details":"Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker could send a specially crafted request and determine if a username exists in the Elasticsearch native realm.","published":"2019-10-30T14:15:11.380Z","modified":"2026-07-08T19:51:12.385774Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.elasticsearch:elasticsearch","fixedVersion":"6.8.4"},{"ecosystem":"Maven","name":"org.elasticsearch:elasticsearch","fixedVersion":"7.4.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://discuss.elastic.co/t/elastic-stack-6-8-4-security-update/204908"},{"type":"ADVISORY","url":"https://discuss.elastic.co/t/elastic-stack-7-4-0-security-update/201831"},{"type":"ADVISORY","url":"https://www.elastic.co/community/security"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T19:51:12.385774Z"}}