Skip to content
ElasticsearchGHSA-hwvv-438r-mhvj

Exposure of Sensitive Information to an Unauthorized Actor

Medium4.3CVE-2021-22134 · Published Mar 18, 2021 · updated Feb 22, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
org.elasticsearch:elasticsearch
Maven
>= 7.6.0, < 7.11.07.11.0
Details and references

A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query against a recently updated document. This affects documents that have been updated and not yet refreshed in the index. This could result in the search disclosing the existence of documents and fields the attacker should not be able to view.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-200, CWE-863
Also known as
BIT-elasticsearch-2021-22134, CVE-2021-22134

More Elasticsearch advisories

All Elasticsearch
DateAdvisory
Mar 182021Privilege Context Switching Error in Elasticsearch
CVE-2020-7020Low3.1fixed in 6.8.13, 7.9.2
Mar 182021Privilege Escalation Flaw in Elasticsearch
CVE-2020-7014Medium8.8fixed in 6.8.8, 7.6.2
Mar 182021Insufficiently Protected Credentials in Elasticsearch
CVE-2021-22132Medium4.8fixed in 7.10.2
Jul 22021API information disclosure flaw in Elasticsearch
CVE-2021-22135Medium5.3fixed in 6.8.15, 7.11.2
Aug 92021Denial of Service in Elasticsearch
CVE-2021-22144Medium5.7fixed in 6.8.17, 7.13.3
Sep 202021Exposure of sensitive information in Elasticsearch
CVE-2021-22147Medium6.5fixed in 7.14.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.