PT-2021-14871 · Elastic · Elasticsearch

Published

2021-09-15

·

Updated

2024-03-06

·

CVE-2021-22147

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Elasticsearch versions prior to 7.14.0
Description: A flaw was discovered in Elasticsearch where document and field level security was not applied to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.
Recommendations: For versions prior to 7.14.0, update to version 7.14.0 or later to resolve the issue. As a temporary workaround, consider restricting access to searchable snapshots until a patch is available.

Fix

Missing Authorization

Incorrect Permission

Weakness Enumeration

Related Identifiers

BIT-ELASTICSEARCH-2021-22147
CVE-2021-22147
GHSA-45H5-R968-5XR7

Affected Products

Elasticsearch