CVE-2021-37940: SSRF
An information disclosure via GET request server-side request forgery vulnerability was discovered with the Workplace Search Github Enterprise Server integration. Using this vulnerability, a malicious Workplace Search admin could use the GHES integration to view hosts that might not be publicly accessible.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-37940?
CVE-2021-37940 is an information disclosure via GET request server-side request forgery vulnerability discovered with the Workplace Search Github Enterprise Server integration.
How does CVE-2021-37940 affect Elastic Enterprise Search?
CVE-2021-37940 affects Elastic Enterprise Search versions up to and excluding 7.16.0.
What is the severity of CVE-2021-37940?
The severity of CVE-2021-37940 is medium, with a CVSS score of 6.8.
How can a malicious Workplace Search admin exploit CVE-2021-37940?
A malicious Workplace Search admin can exploit CVE-2021-37940 by using the GHES integration to view hosts that might not be publicly accessible.
Is there a security update available for CVE-2021-37940?
Yes, a security update is available for CVE-2021-37940. Please refer to https://discuss.elastic.co/t/enterprise-search-7-16-0-security-update/291146 for more information.