ElasticsearchGHSA-45h5-r968-5xr7
Exposure of sensitive information in Elasticsearch
Medium6.5CVE-2021-22147 · Published Sep 20, 2021 · updated Feb 17, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.elasticsearch:elasticsearch Maven | >= 7.11.0, < 7.14.0 | 7.14.0 |
Details and references
A flaw was discovered in Elasticsearch where document and field level security was not applied to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.
More Elasticsearch advisories
All Elasticsearch| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 92021 | Denial of Service in Elasticsearch CVE-2021-22144Medium5.7fixed in 6.8.17, 7.13.3 | Medium5.7 | 6.8.17, 7.13.3 |
| Jul 22021 | API information disclosure flaw in Elasticsearch CVE-2021-22135Medium5.3fixed in 6.8.15, 7.11.2 | Medium5.3 | 6.8.15, 7.11.2 |
| Mar 42022 | Elasticsearch privilege escalation CVE-2022-23708Medium4.3fixed in 7.17.1 | Medium4.3 | 7.17.1 |
| Mar 182021 | Insufficiently Protected Credentials in Elasticsearch CVE-2021-22132Medium4.8fixed in 7.10.2 | Medium4.8 | 7.10.2 |
| Mar 182021 | Privilege Escalation Flaw in Elasticsearch CVE-2020-7014Medium8.8fixed in 6.8.8, 7.6.2 | Medium8.8 | 6.8.8, 7.6.2 |
| Mar 182021 | Privilege Context Switching Error in Elasticsearch CVE-2020-7020Low3.1fixed in 6.8.13, 7.9.2 | Low3.1 | 6.8.13, 7.9.2 |