SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-22132

Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API.

MEDIUM 4.8EPSS 1.24%

Does this matter?

Lower severity and a low EPSS score (1.24%). Track it; it rarely justifies an emergency change on its own.

Description

Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This issue is fixed in Elasticsearch 7.10.2

CVSS 3.1
4.8 MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
EPSS
1.24% probability · 67th percentile
CISA KEV
Not listed
Weakness
CWE-522
Affected
elastic/elasticsearch · oracle/communications cloud native core automated test suite
Source
security@elastic.co

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.