Логотип exploitDog
bind:CVE-2021-22132
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-22132

Количество 5

Количество 5

ubuntu логотип

CVE-2021-22132

около 5 лет назад

Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This issue is fixed in Elasticsearch 7.10.2

CVSS3: 4.8
EPSS: Низкий
redhat логотип

CVE-2021-22132

около 5 лет назад

Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This issue is fixed in Elasticsearch 7.10.2

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2021-22132

около 5 лет назад

Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This issue is fixed in Elasticsearch 7.10.2

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2021-22132

около 5 лет назад

Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosu ...

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-5fvx-2jj3-6mff

почти 5 лет назад

Insufficiently Protected Credentials in Elasticsearch

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-22132

Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This issue is fixed in Elasticsearch 7.10.2

CVSS3: 4.8
0%
Низкий
около 5 лет назад
redhat логотип
CVE-2021-22132

Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This issue is fixed in Elasticsearch 7.10.2

CVSS3: 4.8
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2021-22132

Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This issue is fixed in Elasticsearch 7.10.2

CVSS3: 4.8
0%
Низкий
около 5 лет назад
debian логотип
CVE-2021-22132

Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosu ...

CVSS3: 4.8
0%
Низкий
около 5 лет назад
github логотип
GHSA-5fvx-2jj3-6mff

Insufficiently Protected Credentials in Elasticsearch

CVSS3: 4.8
0%
Низкий
почти 5 лет назад

Уязвимостей на страницу