Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-22134

Опубликовано: 01 мар. 2021
Источник: redhat
CVSS3: 2.6
EPSS Низкий

Описание

A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query against a recently updated document. This affects documents that have been updated and not yet refreshed in the index. This could result in the search disclosing the existence of documents and fields the attacker should not be able to view.

A flaw was found in elasticsearch. Get requests do not properly apply security permissions when executing a query against a recently updated document. This affects documents that have been updated and not yet refreshed in the index. This could result in the search disclosing the existence of documents and fields the attacker should not be able to view. A mitigating factor to this flaw is an attacker must know the document ID to run the get request.

Отчет

In Elasticsearch, Document and Field Level Security is an enterprise only feature [1]. Hence the open source version is unaffected by this vulnerability. [1] https://www.elastic.co/subscriptions

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Decision Manager 7elasticsearchNot affected
Red Hat Fuse 7elasticsearchNot affected
Red Hat Integration Camel K 1elasticsearchNot affected
Red Hat JBoss Fuse 6elasticsearchNot affected
Red Hat JBoss Fuse Service Works 6elasticsearchNot affected
Red Hat OpenShift Container Platform 3.11openshift3/ose-logging-elasticsearch5Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-logging-elasticsearch5Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-logging-elasticsearch6Not affected
Red Hat OpenStack Platform 10 (Newton)python-elasticsearchNot affected
Red Hat Process Automation 7elasticsearchNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=1934745elasticsearch: requests do not properly apply security permissions when executing a query against a recently updated document

EPSS

Процентиль: 62%
0.01112
Низкий

2.6 Low

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 5 лет назад

A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query against a recently updated document. This affects documents that have been updated and not yet refreshed in the index. This could result in the search disclosing the existence of documents and fields the attacker should not be able to view.

CVSS3: 4.3
nvd
больше 5 лет назад

A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query against a recently updated document. This affects documents that have been updated and not yet refreshed in the index. This could result in the search disclosing the existence of documents and fields the attacker should not be able to view.

CVSS3: 4.3
msrc
больше 4 лет назад

A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query against a recently updated document. This affects documents that have been updated and not yet refreshed in the index. This could result in the search disclosing the existence of documents and fields the attacker should not be able to view.

CVSS3: 4.3
debian
больше 5 лет назад

A document disclosure flaw was found in Elasticsearch versions after 7 ...

CVSS3: 4.3
github
больше 5 лет назад

Exposure of Sensitive Information to an Unauthorized Actor

EPSS

Процентиль: 62%
0.01112
Низкий

2.6 Low

CVSS3