CVE-2021-31828
An SSRF issue in Open Distro for Elasticsearch (ODFE) before 1.13.1.0 allows an existing privileged user to enumerate listening services or interact with configured resources via HTTP requests exceeding the Alerting plugin's intended scope.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.89%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An SSRF issue in Open Distro for Elasticsearch (ODFE) before 1.13.1.0 allows an existing privileged user to enumerate listening services or interact with configured resources via HTTP requests exceeding the Alerting plugin's intended scope.
- CVSS 3.1
- 7.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
- EPSS
- 0.89% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-918
- Affected
- amazon/open distro
- Source
- cve@mitre.org
References
- https://github.com/opendistro-for-elasticsearch/alerting/pull/353Patch, Third Party Advisory
- https://opendistro.github.io/for-elasticsearch-docs/version-history/Release Notes, Third Party Advisory
- https://rotem-bar.com/ssrf-in-open-distro-for-elasticsearch-cve-2021-31828Third Party Advisory
- https://github.com/opendistro-for-elasticsearch/alerting/pull/353Patch, Third Party Advisory
- https://opendistro.github.io/for-elasticsearch-docs/version-history/Release Notes, Third Party Advisory
- https://rotem-bar.com/ssrf-in-open-distro-for-elasticsearch-cve-2021-31828Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.