Elasticsearch Anonymous User Vulnerability in Elastic Cloud Enterprise by Elastic
CVE-2021-22146
Key Information:
- Vendor
- Elastic
- Status
- Vendor
- CVE Published:
- 21 July 2021
Badges
Summary
Elastic Cloud Enterprise includes a default setting that enables the 'anonymous' user for all deployed clusters. While this user is designed with no permissions, it poses a risk as an attacker can exploit this configuration to gather sensitive information regarding the architecture and details of the cluster. This vulnerability could potentially lead to more severe security issues if left unaddressed, allowing unauthorized insights into the system's structure.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
18% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved