Document Disclosure Flaw in Elasticsearch by Elastic
CVE-2021-22137
5.3MEDIUM
What is CVE-2021-22137?
A document disclosure flaw exists in Elasticsearch versions prior to 7.11.2 and 6.8.15 that compromises Document and Field Level Security. During specific cross-cluster search queries, the security permissions are not appropriately maintained, leading to unintended access. This may allow attackers to uncover the existence of sensitive documents and indices, even if they should not have permissions to view them, significantly raising the risk of data exposure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Elasticsearch before 7.11.2 and 6.8.15
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved