First published: Tue Dec 07 2021(Updated: )
An information disclosure via GET request server-side request forgery vulnerability was discovered with the Workplace Search Github Enterprise Server integration. Using this vulnerability, a malicious Workplace Search admin could use the GHES integration to view hosts that might not be publicly accessible.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic Enterprise Search | <7.16.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-37940 is an information disclosure via GET request server-side request forgery vulnerability discovered with the Workplace Search Github Enterprise Server integration.
CVE-2021-37940 affects Elastic Enterprise Search versions up to and excluding 7.16.0.
The severity of CVE-2021-37940 is medium, with a CVSS score of 6.8.
A malicious Workplace Search admin can exploit CVE-2021-37940 by using the GHES integration to view hosts that might not be publicly accessible.
Yes, a security update is available for CVE-2021-37940. Please refer to https://discuss.elastic.co/t/enterprise-search-7-16-0-security-update/291146 for more information.