Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q394-h7f5-7f44

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Generation of Error Message Containing Sensitive Information in Elasticsearch

A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer. This buffer could contain sensitive information such as Elasticsearch documents or authentication details.

Пакеты

Наименование

org.elasticsearch.client:elasticsearch-rest-client

maven
Затронутые версииВерсия исправления

>= 7.10.0, <= 7.13.3

7.13.4

EPSS

Процентиль: 99%
0.67928
Средний

6.5 Medium

CVSS3

Дефекты

CWE-200
CWE-209

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 4 лет назад

A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer. This buffer could contain sensitive information such as Elasticsearch documents or authentication details.

CVSS3: 7.3
redhat
больше 4 лет назад

A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer. This buffer could contain sensitive information such as Elasticsearch documents or authentication details.

CVSS3: 6.5
nvd
больше 4 лет назад

A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer. This buffer could contain sensitive information such as Elasticsearch documents or authentication details.

CVSS3: 6.5
debian
больше 4 лет назад

A memory disclosure vulnerability was identified in Elasticsearch 7.10 ...

EPSS

Процентиль: 99%
0.67928
Средний

6.5 Medium

CVSS3

Дефекты

CWE-200
CWE-209