VulnerabilityModified
CVE-2021-22147
This could lead to an authenticated user gaining access to information that they are unauthorized to view.
MEDIUM 6.5EPSS 1.04%
Does this matter?
Lower severity and a low EPSS score (1.04%). Track it; it rarely justifies an emergency change on its own.
Description
Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.04% probability · 62th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732, CWE-862
- Affected
- elastic/elasticsearch
- Source
- security@elastic.co
References
- https://discuss.elastic.co/t/elastic-stack-7-14-0-security-update/280344Vendor Advisory
- https://security.netapp.com/advisory/ntap-20211008-0002/Third Party Advisory
- https://www.elastic.co/community/security/Vendor Advisory
- https://discuss.elastic.co/t/elastic-stack-7-14-0-security-update/280344Vendor Advisory
- https://security.netapp.com/advisory/ntap-20211008-0002/Third Party Advisory
- https://www.elastic.co/community/security/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.