CVE-2021-22135

Description

Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API when Document and Field Level Security are enabled. The suggester and profile API are normally disabled for an index when document level security is enabled on the index. Certain queries are able to enable the profiler and suggester which could lead to disclosing the existence of documents and fields the attacker should not be able to view.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.153

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-22137,CVE-2021-22135 are fixed in Elasticsearch Core 7.11.2Windows
Vulnerabilities CVE-2021-22137,CVE-2021-22135 are fixed in Elasticsearch Core 6.8.15Windows
Vulnerabilities CVE-2021-22137,CVE-2021-22135 are fixed in Elasticsearch Core for Linux 7.11.2Linux
Vulnerabilities CVE-2021-22137,CVE-2021-22135 are fixed in Elasticsearch Core for Linux 6.8.15Linux
Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-22135)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234