Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-22137

Опубликовано: 23 мар. 2021
Источник: redhat
CVSS3: 2.6
EPSS Низкий

Описание

In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosure flaw was found when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain cross-cluster search queries. This could result in the search disclosing the existence of documents the attacker should not be able to view. This could result in an attacker gaining additional insight into potentially sensitive indices.

Отчет

In Elasticsearch, Document and Field Level Security is an enterprise only feature [1]. Hence the open source version is unaffected by this vulnerability. [1] https://www.elastic.co/subscriptions

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel8Not affected
Red Hat Decision Manager 7elasticsearchFix deferred
Red Hat Fuse 7elasticsearchFix deferred
Red Hat JBoss Fuse 6elasticsearchOut of support scope
Red Hat OpenShift Container Platform 3.11openshift3/ose-logging-elasticsearch5Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-logging-elasticsearch5Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-logging-elasticsearch6Not affected
Red Hat Process Automation 7elasticsearchFix deferred
RHAF Camel-K 1.8elasticsearchFixedRHSA-2022:640709.09.2022
RHINT Camel-Q 2.7elasticsearchFixedRHSA-2022:560619.07.2022

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1943189elasticsearch: Document disclosure flaw when Document or Field Level Security is used

EPSS

Процентиль: 29%
0.00105
Низкий

2.6 Low

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 4 лет назад

In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosure flaw was found when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain cross-cluster search queries. This could result in the search disclosing the existence of documents the attacker should not be able to view. This could result in an attacker gaining additional insight into potentially sensitive indices.

CVSS3: 5.3
nvd
больше 4 лет назад

In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosure flaw was found when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain cross-cluster search queries. This could result in the search disclosing the existence of documents the attacker should not be able to view. This could result in an attacker gaining additional insight into potentially sensitive indices.

CVSS3: 5.3
debian
больше 4 лет назад

In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosu ...

CVSS3: 5.3
github
больше 3 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch

EPSS

Процентиль: 29%
0.00105
Низкий

2.6 Low

CVSS3