Vulnerability Name: | CVE-2021-22132 (CCN-194942) | ||||||||||||
Assigned: | 2021-01-14 | ||||||||||||
Published: | 2021-01-14 | ||||||||||||
Updated: | 2022-05-12 | ||||||||||||
Summary: | Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This issue is fixed in Elasticsearch 7.10.2 | ||||||||||||
CVSS v3 Severity: | 4.8 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N) 4.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
4.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:N/AC:H/Au:S/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-522 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-22132 Source: CCN Type: Elasticsearch ESA-2021-01 Elasticsearch authorization-header storage issue Source: MISC Type: Release Notes, Vendor Advisory https://discuss.elastic.co/t/elasticsearch-7-10-2-security-update/261164 Source: XF Type: UNKNOWN elastic-cve202122132-info-disc(194942) Source: CONFIRM Type: Third Party Advisory https://security.netapp.com/advisory/ntap-20210219-0004/ Source: CCN Type: IBM Security Bulletin 6495845 (Observability with Instana) Vulnerability affects IBM Observability with Instana Source: CCN Type: Oracle CPUApr2022 Oracle Critical Patch Update Advisory - April 2022 Source: MISC Type: Patch, Third Party Advisory https://www.oracle.com/security-alerts/cpuapr2022.html | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |