← Back

CVE-2021-22132

nvd nist
Published: Jan 14, 2021Modified: Nov 21, 2024

JSON object

Loading...
4.8
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
Exploitability: 1.2 / Impact: 3.6
Source: NVD

Description

Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This issue is fixed in Elasticsearch 7.10.2

Affected (2)

1 product
Elasticsearch
1 product
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 7.7.0 to 7.10.2
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.8.0

References (6)

Source: security@elastic.co
Release NotesVendor Advisory
Source: security@elastic.co
Third Party Advisory
Source: security@elastic.co
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.