Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-22145

Опубликовано: 21 июл. 2021
Источник: nvd
CVSS3: 6.5
CVSS2: 4
EPSS Средний

Описание

A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer. This buffer could contain sensitive information such as Elasticsearch documents or authentication details.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
Версия от 7.10.0 (включая) до 7.13.3 (включая)
Конфигурация 2
cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.8.0:*:*:*:*:*:*:*

EPSS

Процентиль: 99%
0.67928
Средний

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-200
CWE-209

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 4 лет назад

A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer. This buffer could contain sensitive information such as Elasticsearch documents or authentication details.

CVSS3: 7.3
redhat
больше 4 лет назад

A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer. This buffer could contain sensitive information such as Elasticsearch documents or authentication details.

CVSS3: 6.5
debian
больше 4 лет назад

A memory disclosure vulnerability was identified in Elasticsearch 7.10 ...

CVSS3: 6.5
github
больше 3 лет назад

Generation of Error Message Containing Sensitive Information in Elasticsearch

EPSS

Процентиль: 99%
0.67928
Средний

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-200
CWE-209