Skip to content
ElasticsearchGHSA-45h5-r968-5xr7

Exposure of sensitive information in Elasticsearch

Medium6.5CVE-2021-22147 · Published Sep 20, 2021 · updated Feb 17, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
org.elasticsearch:elasticsearch
Maven
>= 7.11.0, < 7.14.07.14.0
Details and references

A flaw was discovered in Elasticsearch where document and field level security was not applied to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-732, CWE-862
Also known as
BIT-elasticsearch-2021-22147, CVE-2021-22147

More Elasticsearch advisories

All Elasticsearch
DateAdvisory
Aug 92021Denial of Service in Elasticsearch
CVE-2021-22144Medium5.7fixed in 6.8.17, 7.13.3
Jul 22021API information disclosure flaw in Elasticsearch
CVE-2021-22135Medium5.3fixed in 6.8.15, 7.11.2
Mar 42022Elasticsearch privilege escalation
CVE-2022-23708Medium4.3fixed in 7.17.1
Mar 182021Insufficiently Protected Credentials in Elasticsearch
CVE-2021-22132Medium4.8fixed in 7.10.2
Mar 182021Privilege Escalation Flaw in Elasticsearch
CVE-2020-7014Medium8.8fixed in 6.8.8, 7.6.2
Mar 182021Privilege Context Switching Error in Elasticsearch
CVE-2020-7020Low3.1fixed in 6.8.13, 7.9.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.