PT-2021-3748 · Elastic · Cloud Enterprise
Published
2021-07-21
·
Updated
2024-03-06
·
CVE-2021-22146
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Elastic Cloud Enterprise versions (affected versions not specified)
Description
The issue is related to the Elasticsearch “anonymous” user being enabled by default in deployed clusters. Although this user has no permissions and cannot query any Elasticsearch APIs by default, an attacker could potentially use it to gain insight into certain details of a deployed cluster. The vulnerability is associated with security configuration errors in the Elastic Cloud Enterprise platform, which could allow a remote attacker to access protected information.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloud Enterprise