VulnerabilityModified
CVE-2021-22132
Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API.
MEDIUM 4.8EPSS 1.24%
Does this matter?
Lower severity and a low EPSS score (1.24%). Track it; it rarely justifies an emergency change on its own.
Description
Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This issue is fixed in Elasticsearch 7.10.2
- CVSS 3.1
- 4.8 MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 1.24% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- elastic/elasticsearch · oracle/communications cloud native core automated test suite
- Source
- security@elastic.co
References
- https://discuss.elastic.co/t/elasticsearch-7-10-2-security-update/261164Release Notes, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20210219-0004/Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://discuss.elastic.co/t/elasticsearch-7-10-2-security-update/261164Release Notes, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20210219-0004/Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.