Document Disclosure Flaw in Elasticsearch by Elastic
CVE-2021-22137
5.3MEDIUM
Summary
A document disclosure flaw exists in Elasticsearch versions prior to 7.11.2 and 6.8.15 that compromises Document and Field Level Security. During specific cross-cluster search queries, the security permissions are not appropriately maintained, leading to unintended access. This may allow attackers to uncover the existence of sensitive documents and indices, even if they should not have permissions to view them, significantly raising the risk of data exposure.
Affected Version(s)
Elasticsearch before 7.11.2 and 6.8.15
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved