Document Disclosure Vulnerability in Elasticsearch by Elastic
CVE-2021-22135
5.3MEDIUM
What is CVE-2021-22135?
Elasticsearch versions prior to 7.11.2 and 6.8.15 exhibit a document disclosure flaw found in the suggester and profile API when Document and Field Level Security are enabled. While these APIs are typically disabled for an index with document level security, certain query patterns can inadvertently enable them. This unintended access may allow attackers to disclose the existence of sensitive documents and fields that should otherwise remain inaccessible.
Affected Version(s)
Elasticsearch before 7.11.2 and 6.8.15