{"api_version":"1","generated_at":"2026-07-23T09:50:06+00:00","cve":"CVE-2020-9387","urls":{"html":"https://cve.report/CVE-2020-9387","api":"https://cve.report/api/cve/CVE-2020-9387.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-9387","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-9387"},"summary":{"title":"CVE-2020-9387","description":"In Mahara 19.04 before 19.04.5 and 19.10 before 19.10.3, account details are shared in the Elasticsearch results for accounts that are not accessible when the config setting 'Isolated institutions' is turned on.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-04-30 13:15:00","updated_at":"2020-05-12 16:03:00"},"problem_types":["CWE-200"],"metrics":[],"references":[{"url":"https://bugs.launchpad.net/mahara/+bug/1836984","name":"https://bugs.launchpad.net/mahara/+bug/1836984","refsource":"CONFIRM","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"Bug #1836984 “Elasticsearch not restricting the user search when...” : Bugs : Mahara","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://mahara.org/interaction/forum/topic.php?id=8612","name":"https://mahara.org/interaction/forum/topic.php?id=8612","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Security Announcements - Security issue relating to the Elasticsearch results and Isolated institutions <18.10.6, <19.04.5, <19.10.3 - Mahara ePortfolio System","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-9387","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-9387","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"9387","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mahara","cpe5":"mahara","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"9387","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mahara","cpe5":"mahara","cpe6":"20.04","cpe7":"rc1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"9387","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mahara","cpe5":"mahara","cpe6":"20.04","cpe7":"rc2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"9387","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mahara","cpe5":"mahara","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"9387","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mahara","cpe5":"mahara","cpe6":"20.04","cpe7":"rc1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"9387","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mahara","cpe5":"mahara","cpe6":"20.04","cpe7":"rc2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-9387","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In Mahara 19.04 before 19.04.5 and 19.10 before 19.10.3, account details are shared in the Elasticsearch results for accounts that are not accessible when the config setting 'Isolated institutions' is turned on."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","name":"https://bugs.launchpad.net/mahara/+bug/1836984","url":"https://bugs.launchpad.net/mahara/+bug/1836984"},{"refsource":"CONFIRM","name":"https://mahara.org/interaction/forum/topic.php?id=8612","url":"https://mahara.org/interaction/forum/topic.php?id=8612"}]}},"nvd":{"publishedDate":"2020-04-30 13:15:00","lastModifiedDate":"2020-05-12 16:03:00","problem_types":["CWE-200"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.5},"severity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*","versionStartIncluding":"19.10","versionEndExcluding":"19.10.3","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mahara:mahara:*:*:*:*:*:*:*:*","versionStartIncluding":"19.04","versionEndExcluding":"19.04.5","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mahara:mahara:20.04:rc2:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mahara:mahara:20.04:rc1:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"9387","Ordinal":"169774","Title":"CVE-2020-9387","CVE":"CVE-2020-9387","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"9387","Ordinal":"1","NoteData":"In Mahara 19.04 before 19.04.5 and 19.10 before 19.10.3, account details are shared in the Elasticsearch results for accounts that are not accessible when the config setting 'Isolated institutions' is turned on.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"9387","Ordinal":"2","NoteData":"2020-04-30","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"9387","Ordinal":"3","NoteData":"2020-04-30","Type":"Other","Title":"Modified"}]}}}