Skip to content
ElasticsearchGHSA-5fvx-2jj3-6mff

Insufficiently Protected Credentials in Elasticsearch

Medium4.8CVE-2021-22132 · Published Mar 18, 2021 · updated Feb 17, 2024

Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This issue is fixed in Elasticsearch 7.10.2

GitHub advisory

Affected versions

PackageAffectedFixed in
org.elasticsearch:elasticsearch
Maven
>= 7.7.0, < 7.10.27.10.2
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-522
Also known as
BIT-elasticsearch-2021-22132, CVE-2021-22132

More Elasticsearch advisories

All Elasticsearch
Advisory
Exposure of sensitive information in Elasticsearch
Medium6.5Sep 20, 2021
Denial of Service in Elasticsearch
Medium5.7Aug 9, 2021
API information disclosure flaw in Elasticsearch
Medium5.3Jul 2, 2021
Privilege Escalation Flaw in Elasticsearch
Medium8.8Mar 18, 2021
Privilege Context Switching Error in Elasticsearch
Low3.1Mar 18, 2021
Exposure of Sensitive Information to an Unauthorized Actor
Medium4.3Mar 18, 2021

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.