Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-22147

Опубликовано: 03 авг. 2021
Источник: redhat
CVSS3: 5.7
EPSS Низкий

Описание

Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.

Отчет

Searchable snapshots feature is only available with enterprise subscription. Opensource version of elasticsearch does not include the searchable snapshots feature and hence not affected by this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel8Not affected
OpenShift Service Mesh 1servicemesh-grafanaNot affected
OpenShift Service Mesh 2.0servicemesh-grafanaNot affected
Red Hat Decision Manager 7elasticsearchNot affected
Red Hat Fuse 7elasticsearchNot affected
Red Hat Integration Camel K 1elasticsearchNot affected
Red Hat JBoss Data Grid 6elasticsearchOut of support scope
Red Hat JBoss Fuse 6elasticsearchOut of support scope
Red Hat JBoss Fuse Service Works 6elasticsearchOut of support scope
Red Hat OpenShift Container Platform 3.11openshift3/ose-logging-elasticsearch5Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1990094elasticsearch: document and field level security was not applied to searchable snapshots

EPSS

Процентиль: 54%
0.00314
Низкий

5.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 4 лет назад

Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.

CVSS3: 6.5
nvd
больше 4 лет назад

Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.

CVSS3: 6.5
debian
больше 4 лет назад

Elasticsearch before 7.14.0 did not apply document and field level sec ...

CVSS3: 6.5
github
больше 4 лет назад

Exposure of sensitive information in Elasticsearch

EPSS

Процентиль: 54%
0.00314
Низкий

5.7 Medium

CVSS3