PT-2021-3748 · Elastic · Cloud Enterprise

Published

2021-07-21

·

Updated

2024-03-06

·

CVE-2021-22146

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Elastic Cloud Enterprise versions (affected versions not specified)
Description The issue is related to the Elasticsearch “anonymous” user being enabled by default in deployed clusters. Although this user has no permissions and cannot query any Elasticsearch APIs by default, an attacker could potentially use it to gain insight into certain details of a deployed cluster. The vulnerability is associated with security configuration errors in the Elastic Cloud Enterprise platform, which could allow a remote attacker to access protected information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

BDU:2021-04001
BIT-ELASTICSEARCH-2021-22146
CVE-2021-22146

Affected Products

Cloud Enterprise