PT-2021-14862 · Elastic · Elasticsearch

Published

2021-03-08

·

Updated

2024-03-06

·

CVE-2021-22134

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Elasticsearch versions after 7.6.0 and before 7.11.0
Description A document disclosure flaw was found when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query against a recently updated document. This affects documents that have been updated and not yet refreshed in the index, potentially disclosing the existence of documents and fields the attacker should not be able to view.
Recommendations For Elasticsearch versions after 7.6.0 and before 7.11.0, update to version 7.11.0 or later to resolve the issue. As a temporary workaround, consider restricting access to recently updated documents until the index is refreshed.

Fix

Incorrect Authorization

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ELASTICSEARCH-2021-22134
CVE-2021-22134
GHSA-HWVV-438R-MHVJ

Affected Products

Elasticsearch