PT-2021-14862 · Elastic · Elasticsearch
Published
2021-03-08
·
Updated
2024-03-06
·
CVE-2021-22134
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Elasticsearch versions after 7.6.0 and before 7.11.0
Description
A document disclosure flaw was found when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query against a recently updated document. This affects documents that have been updated and not yet refreshed in the index, potentially disclosing the existence of documents and fields the attacker should not be able to view.
Recommendations
For Elasticsearch versions after 7.6.0 and before 7.11.0, update to version 7.11.0 or later to resolve the issue. As a temporary workaround, consider restricting access to recently updated documents until the index is refreshed.
Fix
Incorrect Authorization
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Elasticsearch