Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-22134

Опубликовано: 01 мар. 2021
Источник: redhat
CVSS3: 2.6

Описание

A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query against a recently updated document. This affects documents that have been updated and not yet refreshed in the index. This could result in the search disclosing the existence of documents and fields the attacker should not be able to view.

A flaw was found in elasticsearch. Get requests do not properly apply security permissions when executing a query against a recently updated document. This affects documents that have been updated and not yet refreshed in the index. This could result in the search disclosing the existence of documents and fields the attacker should not be able to view. A mitigating factor to this flaw is an attacker must know the document ID to run the get request.

Отчет

In Elasticsearch, Document and Field Level Security is an enterprise only feature [1]. Hence the open source version is unaffected by this vulnerability. [1] https://www.elastic.co/subscriptions

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Decision Manager 7elasticsearchNot affected
Red Hat Fuse 7elasticsearchNot affected
Red Hat Integration Camel K 1elasticsearchNot affected
Red Hat JBoss Fuse 6elasticsearchNot affected
Red Hat JBoss Fuse Service Works 6elasticsearchNot affected
Red Hat OpenShift Container Platform 3.11openshift3/ose-logging-elasticsearch5Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-logging-elasticsearch5Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-logging-elasticsearch6Not affected
Red Hat OpenStack Platform 10 (Newton)python-elasticsearchNot affected
Red Hat Process Automation 7elasticsearchNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=1934745elasticsearch: requests do not properly apply security permissions when executing a query against a recently updated document

2.6 Low

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 5 лет назад

A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query against a recently updated document. This affects documents that have been updated and not yet refreshed in the index. This could result in the search disclosing the existence of documents and fields the attacker should not be able to view.

CVSS3: 4.3
nvd
почти 5 лет назад

A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query against a recently updated document. This affects documents that have been updated and not yet refreshed in the index. This could result in the search disclosing the existence of documents and fields the attacker should not be able to view.

CVSS3: 4.3
msrc
около 4 лет назад

A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query against a recently updated document. This affects documents that have been updated and not yet refreshed in the index. This could result in the search disclosing the existence of documents and fields the attacker should not be able to view.

CVSS3: 4.3
debian
почти 5 лет назад

A document disclosure flaw was found in Elasticsearch versions after 7 ...

CVSS3: 4.3
github
почти 5 лет назад

Exposure of Sensitive Information to an Unauthorized Actor

2.6 Low

CVSS3