Skip to content
ElasticsearchGHSA-62ww-4p3p-7fhj

API information disclosure flaw in Elasticsearch

Medium5.3CVE-2021-22135 · Published Jul 2, 2021 · updated Feb 17, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
org.elasticsearch:elasticsearch
Maven
>= 7.0.0, < 7.11.27.11.2
< 6.8.156.8.15
Details and references

Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API when Document and Field Level Security are enabled. The suggester and profile API are normally disabled for an index when document level security is enabled on the index. Certain queries are able to enable the profiler and suggester which could lead to disclosing the existence of documents and fields the attacker should not be able to view.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-200
Also known as
BIT-elasticsearch-2021-22135, CVE-2021-22135

More Elasticsearch advisories

All Elasticsearch
DateAdvisory
Aug 92021Denial of Service in Elasticsearch
CVE-2021-22144Medium5.7fixed in 6.8.17, 7.13.3
Sep 202021Exposure of sensitive information in Elasticsearch
CVE-2021-22147Medium6.5fixed in 7.14.0
Mar 182021Insufficiently Protected Credentials in Elasticsearch
CVE-2021-22132Medium4.8fixed in 7.10.2
Mar 182021Privilege Escalation Flaw in Elasticsearch
CVE-2020-7014Medium8.8fixed in 6.8.8, 7.6.2
Mar 182021Privilege Context Switching Error in Elasticsearch
CVE-2020-7020Low3.1fixed in 6.8.13, 7.9.2
Mar 182021Exposure of Sensitive Information to an Unauthorized Actor
CVE-2021-22134Medium4.3fixed in 7.11.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.