CVE-2021-22132Insufficiently Protected Credentials in Elasticsearch

Severity
4.8MEDIUMNVD
EPSS
0.4%
top 38.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 14
Latest updateApr 15

Description

Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This issue is fixed in Elasticsearch 7.10.2

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:NExploitability: 1.2 | Impact: 3.6

Affected Packages3 packages

Patches

🔴Vulnerability Details

4
GHSA
Insufficiently Protected Credentials in Elasticsearch2021-03-18
OSV
Insufficiently Protected Credentials in Elasticsearch2021-03-18
CVEList
CVE-2021-22132: Elasticsearch versions 72021-01-14
OSV
CVE-2021-22132: Elasticsearch versions 72021-01-14

📋Vendor Advisories

2
Oracle
Oracle Oracle Communications Risk Matrix: Automated Test Suite Framework (Elasticsearch) — CVE-2021-221322022-04-15
Red Hat
elasticsearch: executing async search improperly stores HTTP headers leading to information disclosure2021-01-14
CVE-2021-22132 — Insufficiently Protected Credentials | cvebase