ElasticsearchGHSA-62ww-4p3p-7fhj
API information disclosure flaw in Elasticsearch
Medium5.3CVE-2021-22135 · Published Jul 2, 2021 · updated Feb 17, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.elasticsearch:elasticsearch Maven | >= 7.0.0, < 7.11.2 | 7.11.2 |
| < 6.8.15 | 6.8.15 |
Details and references
Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API when Document and Field Level Security are enabled. The suggester and profile API are normally disabled for an index when document level security is enabled on the index. Certain queries are able to enable the profiler and suggester which could lead to disclosing the existence of documents and fields the attacker should not be able to view.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-200
- Also known as
- BIT-elasticsearch-2021-22135, CVE-2021-22135
More Elasticsearch advisories
All Elasticsearch| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 92021 | Denial of Service in Elasticsearch CVE-2021-22144Medium5.7fixed in 6.8.17, 7.13.3 | Medium5.7 | 6.8.17, 7.13.3 |
| Sep 202021 | Exposure of sensitive information in Elasticsearch CVE-2021-22147Medium6.5fixed in 7.14.0 | Medium6.5 | 7.14.0 |
| Mar 182021 | Insufficiently Protected Credentials in Elasticsearch CVE-2021-22132Medium4.8fixed in 7.10.2 | Medium4.8 | 7.10.2 |
| Mar 182021 | Privilege Escalation Flaw in Elasticsearch CVE-2020-7014Medium8.8fixed in 6.8.8, 7.6.2 | Medium8.8 | 6.8.8, 7.6.2 |
| Mar 182021 | Privilege Context Switching Error in Elasticsearch CVE-2020-7020Low3.1fixed in 6.8.13, 7.9.2 | Low3.1 | 6.8.13, 7.9.2 |
| Mar 182021 | Exposure of Sensitive Information to an Unauthorized Actor CVE-2021-22134Medium4.3fixed in 7.11.0 | Medium4.3 | 7.11.0 |