Логотип exploitDog
bind:CVE-2021-22146
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-22146

Количество 3

Количество 3

nvd логотип

CVE-2021-22146

больше 4 лет назад

All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the default setting the anonymous user has no permissions and is unable to successfully query any Elasticsearch APIs, an attacker could leverage the anonymous user to gain insight into certain details of a deployed cluster.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-wxcx-pqjc-2pp9

больше 3 лет назад

All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the default setting the anonymous user has no permissions and is unable to successfully query any Elasticsearch APIs, an attacker could leverage the anonymous user to gain insight into certain details of a deployed cluster.

CVSS3: 7.5
EPSS: Средний
fstec логотип

BDU:2021-04001

больше 4 лет назад

Уязвимость облачной платформы аналитики Elastic Cloud Enterprise, связанная с ошибками в настройках безопасности, позволяющая нарушителю получить доступ к защищаемой информации

CVSS3: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-22146

All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the default setting the anonymous user has no permissions and is unable to successfully query any Elasticsearch APIs, an attacker could leverage the anonymous user to gain insight into certain details of a deployed cluster.

CVSS3: 7.5
30%
Средний
больше 4 лет назад
github логотип
GHSA-wxcx-pqjc-2pp9

All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the default setting the anonymous user has no permissions and is unable to successfully query any Elasticsearch APIs, an attacker could leverage the anonymous user to gain insight into certain details of a deployed cluster.

CVSS3: 7.5
30%
Средний
больше 3 лет назад
fstec логотип
BDU:2021-04001

Уязвимость облачной платформы аналитики Elastic Cloud Enterprise, связанная с ошибками в настройках безопасности, позволяющая нарушителю получить доступ к защищаемой информации

CVSS3: 7.5
30%
Средний
больше 4 лет назад

Уязвимостей на страницу