{"id":"CVE-2019-7619","details":"Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker could send a specially crafted request and determine if a username exists in the Elasticsearch native realm.","aliases":["GHSA-hxp8-r9g3-grfr"],"modified":"2026-07-08T19:51:12.385774Z","published":"2019-10-30T14:15:11.380Z","references":[{"type":"ADVISORY","url":"https://discuss.elastic.co/t/elastic-stack-6-8-4-security-update/204908"},{"type":"ADVISORY","url":"https://discuss.elastic.co/t/elastic-stack-7-4-0-security-update/201831"},{"type":"ADVISORY","url":"https://www.elastic.co/community/security"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/elasticsearch","events":[{"introduced":"8453f7701de25c467ce08088ddddac185cb8028c"},{"last_affected":"0c48c0e73be564f3a8a286b2165d50de2fbbb661"},{"introduced":"b7e28a7232616c7a21bc879a535d801b8553ba77"},{"last_affected":"1c1faf179b40cccb785fb00bf32b2a91176d6c85"}],"database_specific":{"cpe":"cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"6.7.0"},{"last_affected":"6.8.3"},{"introduced":"7.0.0"},{"last_affected":"7.3.2"}],"source":"CPE_RANGE"}}],"versions":["v6.8.3","v6.8.2","v6.8.1","v6.8.0","v6.7.2","v6.7.1","v6.7.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-7619.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}