CVE-2021-22134: Infoleak
A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query against a recently updated document. This affects documents that have been updated and not yet refreshed in the index. This could result in the search disclosing the existence of documents and fields the attacker should not be able to view.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this document disclosure flaw in Elasticsearch?
The vulnerability ID is CVE-2021-22134.
What is the affected software for this vulnerability?
The affected software includes Elasticsearch versions after 7.6.0 and before 7.11.0 as well as Oracle Communications Cloud Native Core Automated Test Suite version 1.8.0.
What is the severity of CVE-2021-22134?
The severity of CVE-2021-22134 is medium with a CVSS score of 4.3.
How does this vulnerability impact Elasticsearch?
This vulnerability allows unauthorized access to documents when Document or Field Level Security is used in Elasticsearch versions after 7.6.0 and before 7.11.0.
How can I mitigate the CVE-2021-22134 vulnerability in Elasticsearch?
To mitigate this vulnerability, upgrade Elasticsearch to version 7.11.0 or newer.