# Enterprise Search 7.9.0 security update

**URL:** <https://discuss.elastic.co/t/enterprise-search-7-9-0-security-update/245457>\
**Category:** Security Announcements\
**Created:** [August 18, 2020, 3:16pm UTC](https://discuss.elastic.co/t/enterprise-search-7-9-0-security-update/245457 "2020-08-18T15:16:01Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![douglasday](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/douglasday/32/74044_2.png) [@douglasday](https://discuss.elastic.co/u/douglasday)\
**Post date:** [August 18, 2020, 3:16pm UTC](https://discuss.elastic.co/t/enterprise-search-7-9-0-security-update/245457/1 "2020-08-18T15:16:01Z")

</div>

**Enterprise Search credential exposure flaw (ESA-2020-11)**

Elastic Enterprise Search versions before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the ‘developer’ role, they will be able to view the administrator API credentials. These credentials could allow the developer user to conduct operations with the same permissions of the App Search administrator.

Thanks to Matt Peel of Silverstripe for reporting this vulnerability.

**Affected Versions**  
All versions before 7.9.0

**Solutions and Mitigations**  
Users should upgrade to Enterprise Search version 7.9.0. Users unable to upgrade can remove the developer role from App Search users and reset their existing API keys.

**CVSSv3: 4.8 - AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N**

**CVE ID: CVE-2020-7018**

---

_[View the full topic](https://discuss.elastic.co/t/enterprise-search-7-9-0-security-update/245457)._
