ElasticsearchGHSA-5fvx-2jj3-6mff
Insufficiently Protected Credentials in Elasticsearch
Medium4.8CVE-2021-22132 · Published Mar 18, 2021 · updated Feb 17, 2024
Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This issue is fixed in Elasticsearch 7.10.2
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.elasticsearch:elasticsearch Maven | >= 7.7.0, < 7.10.2 | 7.10.2 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-522
- Also known as
- BIT-elasticsearch-2021-22132, CVE-2021-22132
More Elasticsearch advisories
All Elasticsearch| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 202021 | Exposure of sensitive information in Elasticsearch | Medium6.5 | 7.14.0 |
| Aug 92021 | Denial of Service in Elasticsearch | Medium5.7 | 6.8.17+1 more |
| Jul 22021 | API information disclosure flaw in Elasticsearch | Medium5.3 | 6.8.15+1 more |
| Mar 182021 | Privilege Escalation Flaw in Elasticsearch | Medium8.8 | 6.8.8+1 more |
| Mar 182021 | Privilege Context Switching Error in Elasticsearch | Low3.1 | 6.8.13+1 more |
| Mar 182021 | Exposure of Sensitive Information to an Unauthorized Actor | Medium4.3 | 7.11.0 |