Vulnerability Name:

CVE-2021-22144 (CCN-206321)

Assigned:2021-07-07
Published:2021-07-07
Updated:2022-05-10
Summary:In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit arbitrary queries to Elasticsearch could create a malicious Grok query that will crash the Elasticsearch node.
CVSS v3 Severity:6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
5.7 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
5.0 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Adjacent
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.5 Medium (CCN CVSS v2 Vector: AV:A/AC:L/Au:S/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Adjacent_Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-674
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2021-22144

Source: CCN
Type: ESA-2021-15
Elasticsearch Denial of Service issue

Source: MISC
Type: Release Notes, Vendor Advisory
https://discuss.elastic.co/t/elasticsearch-7-13-3-and-6-8-17-security-update/278100

Source: XF
Type: UNKNOWN
elasticsearch-cve202122144-dos(206321)

Source: CONFIRM
Type: Third Party Advisory
https://security.netapp.com/advisory/ntap-20210827-0006/

Source: CCN
Type: IBM Security Bulletin 6499713 (Cloud Pak for Integration)
Operations Dashboard is vulnerable to Elasticsearch Go vulnerabilities (CVE-2021-22144 & CVE-2021-22145)

Source: CCN
Type: IBM Security Bulletin 6526540 (Resilient OnPrem)
IBM Security SOAR is using a component with known vulnerabilities - Elasticsearch ( CVE-2021-22144, CVE-2021-22145, CVE-2021-22147)

Source: CCN
Type: IBM Security Bulletin 6538168 (Cloud Private)
Vulnerability in Elasticsearch affects IBM Cloud Private (CVE-2021-22144)

Source: CCN
Type: IBM Security Bulletin 6831813 (Netcool Operations Insight)
Netcool Operations Insight v1.6.6 contains fixes for multiple security vulnerabilities.

Source: MISC
Type: Patch, Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2021-22144

Vulnerable Configuration:Configuration 1:
  • cpe:/a:elastic:elasticsearch:*:*:*:*:*:*:*:* (Version < 6.8.17)
  • OR cpe:/a:elastic:elasticsearch:*:*:*:*:*:*:*:* (Version >= 7.0.0 and < 7.13.3)

  • Configuration 2:
  • cpe:/a:oracle:communications_cloud_native_core_automated_test_suite:1.8.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:elastic:elasticsearch:6.8.14:*:*:*:*:*:*:*
  • OR cpe:/a:elastic:elasticsearch:6.8.15:*:*:*:*:*:*:*
  • OR cpe:/a:elastic:elasticsearch:7.13.0:*:*:*:*:*:*:*
  • OR cpe:/a:elastic:elasticsearch:7.13.1:*:*:*:*:*:*:*
  • OR cpe:/a:elastic:elasticsearch:7.13.2:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:cloud_private:3.2.1:cd:*:*:*:*:*:*
  • OR cpe:/a:ibm:cloud_private:3.2.2:cd:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    elastic elasticsearch *
    elastic elasticsearch *
    oracle communications cloud native core automated test suite 1.8.0
    elastic elasticsearch 6.8.14
    elastic elasticsearch 6.8.15
    elastic elasticsearch 7.13.0
    elastic elasticsearch 7.13.1
    elastic elasticsearch 7.13.2
    ibm cloud private 3.2.1 cd
    ibm cloud private 3.2.2 cd