First published: Wed Jul 21 2021(Updated: )
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer. This buffer could contain sensitive information such as Elasticsearch documents or authentication details.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic Elasticsearch | >=7.10.0<=7.13.3 | |
oracle communications Cloud native core automated test suite | =1.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22145 is a memory disclosure vulnerability in Elasticsearch 7.10.0 to 7.13.3 error reporting that allows a user to access previously used portions of a data buffer through a malformed query.
Elasticsearch versions 7.10.0 to 7.13.3 are affected by CVE-2021-22145.
CVE-2021-22145 has a severity rating of 6.5 (medium).
An attacker can exploit CVE-2021-22145 by submitting a malformed query to Elasticsearch that triggers an error message containing previously used data.
Yes, Elastic has released a security update for Elasticsearch version 7.13.4 to address CVE-2021-22145.