Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-22140

Опубликовано: 27 апр. 2021
Источник: redhat
CVSS3: 9.3
EPSS Низкий

Описание

Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta feature. Using this vector, an attacker whose website is being crawled by App Search could craft a malicious sitemap.xml to traverse the filesystem of the host running the instance and obtain sensitive files.

A flaw was found in Elastic Enterprise Search. An attacker, using an XML External Entity Injection (XXE) issue in the App Search web crawler, could craft a malicious sitemap.xml allowing the crawler to traverse the filesystem of the host running the instance and obtain sensitive files. The highest threat from this vulnerability is to data confidentiality.

Отчет

This vulnerability only affects the 'App Search web crawler beta feature' for Elastic Enterprise Search, as noted in the Elastic.co advisory [1]. That feature is not available in the upstream elasticsearch open source namespace on Github [2]. [1] https://discuss.elastic.co/t/7-12-1-security-update/271433 [2] https://github.com/elastic

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 1servicemesh-grafanaNot affected
OpenShift Service Mesh 2.0servicemesh-grafanaNot affected
Red Hat Decision Manager 7elasticsearchNot affected
Red Hat Fuse 7elasticsearchNot affected
Red Hat Integration Camel K 1elasticsearchNot affected
Red Hat JBoss Data Grid 6elasticsearchNot affected
Red Hat JBoss Fuse 6elasticsearchNot affected
Red Hat JBoss Fuse Service Works 6elasticsearchNot affected
Red Hat OpenShift Container Platform 3.11openshift3/ose-logging-elasticsearch5Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-logging-elasticsearch5Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1955289Search: App Search XML External Entity Injection

EPSS

Процентиль: 59%
0.00376
Низкий

9.3 Critical

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 4 лет назад

Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta feature. Using this vector, an attacker whose website is being crawled by App Search could craft a malicious sitemap.xml to traverse the filesystem of the host running the instance and obtain sensitive files.

github
больше 3 лет назад

Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta feature. Using this vector, an attacker whose website is being crawled by App Search could craft a malicious sitemap.xml to traverse the filesystem of the host running the instance and obtain sensitive files.

EPSS

Процентиль: 59%
0.00376
Низкий

9.3 Critical

CVSS3