Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-22135

Опубликовано: 23 мар. 2021
Источник: redhat
CVSS3: 3.1

Описание

Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API when Document and Field Level Security are enabled. The suggester and profile API are normally disabled for an index when document level security is enabled on the index. Certain queries are able to enable the profiler and suggester which could lead to disclosing the existence of documents and fields the attacker should not be able to view.

Отчет

In Elasticsearch, Document and Field Level Security is an enterprise only feature [1]. Hence the open source version is unaffected by this vulnerability. [1] https://www.elastic.co/subscriptions

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel8Not affected
Red Hat Decision Manager 7elasticsearchFix deferred
Red Hat Fuse 7elasticsearchFix deferred
Red Hat Integration Camel K 1elasticsearchFix deferred
Red Hat JBoss Fuse 6elasticsearchOut of support scope
Red Hat OpenShift Container Platform 3.11openshift3/ose-logging-elasticsearch5Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-logging-elasticsearch5Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-logging-elasticsearch6Not affected
Red Hat Process Automation 7elasticsearchAffected
RHINT Camel-Q 2.7elasticsearchFixedRHSA-2022:560619.07.2022

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1943184elasticsearch: Document disclosure flaw in the Elasticsearch suggester

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 4 лет назад

Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API when Document and Field Level Security are enabled. The suggester and profile API are normally disabled for an index when document level security is enabled on the index. Certain queries are able to enable the profiler and suggester which could lead to disclosing the existence of documents and fields the attacker should not be able to view.

CVSS3: 5.3
nvd
больше 4 лет назад

Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API when Document and Field Level Security are enabled. The suggester and profile API are normally disabled for an index when document level security is enabled on the index. Certain queries are able to enable the profiler and suggester which could lead to disclosing the existence of documents and fields the attacker should not be able to view.

CVSS3: 5.3
debian
больше 4 лет назад

Elasticsearch versions before 7.11.2 and 6.8.15 contain a document dis ...

CVSS3: 5.3
github
больше 4 лет назад

API information disclosure flaw in Elasticsearch

3.1 Low

CVSS3