{"api_version":"1","generated_at":"2026-07-23T13:40:14+00:00","cve":"CVE-2020-9386","urls":{"html":"https://cve.report/CVE-2020-9386","api":"https://cve.report/api/cve/CVE-2020-9386.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-9386","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-9386"},"summary":{"title":"CVE-2020-9386","description":"In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, file metadata information is disclosed to group members in the Elasticsearch result list despite them not having access to that artefact anymore.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-03-09 16:15:00","updated_at":"2022-10-07 00:13:00"},"problem_types":["CWE-200"],"metrics":[],"references":[{"url":"https://bugs.launchpad.net/mahara/+bug/1840201","name":"https://bugs.launchpad.net/mahara/+bug/1840201","refsource":"MISC","tags":[],"title":"Bug #1840201 “Elastic search: Search results are not restricted ...” : Bugs : Mahara","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://mahara.org/interaction/forum/topic.php?id=8589","name":"https://mahara.org/interaction/forum/topic.php?id=8589","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Security Announcements - Security issue relating to incorrect access control in Elasticsearch results <18.10.5, <19.04.4, <19.10.2  - Mahara ePortfolio System","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-9386","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-9386","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"9386","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mahara","cpe5":"mahara","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"9386","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mahara","cpe5":"mahara","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-9386","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, file metadata information is disclosed to group members in the Elasticsearch result list despite them not having access to that artefact anymore."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://bugs.launchpad.net/mahara/+bug/1840201","url":"https://bugs.launchpad.net/mahara/+bug/1840201"},{"refsource":"CONFIRM","name":"https://mahara.org/interaction/forum/topic.php?id=8589","url":"https://mahara.org/interaction/forum/topic.php?id=8589"}]}},"nvd":{"publishedDate":"2020-03-09 16:15:00","lastModifiedDate":"2022-10-07 00:13:00","problem_types":["CWE-200"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.5","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*","versionStartIncluding":"19.04.0","versionEndExcluding":"19.04.4","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*","versionStartIncluding":"19.10.0","versionEndExcluding":"19.10.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"9386","Ordinal":"169773","Title":"CVE-2020-9386","CVE":"CVE-2020-9386","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"9386","Ordinal":"1","NoteData":"In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, file metadata information is disclosed to group members in the Elasticsearch result list despite them not having access to that artefact anymore.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"9386","Ordinal":"2","NoteData":"2020-03-09","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"9386","Ordinal":"3","NoteData":"2020-03-13","Type":"Other","Title":"Modified"}]}}}