CVE-2021-22147Incorrect Permission Assignment in Elasticsearch

Severity
6.5MEDIUMNVD
EPSS
0.3%
top 45.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 15
Latest updateSep 20

Description

Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDelastic/elasticsearch7.11.07.14.0
CVEListV5elastic/elasticsearchversions 7.11.0 to 7.13.4

🔴Vulnerability Details

4
OSV
Exposure of sensitive information in Elasticsearch2021-09-20
GHSA
Exposure of sensitive information in Elasticsearch2021-09-20
OSV
CVE-2021-22147: Elasticsearch before 72021-09-15
CVEList
CVE-2021-22147: Elasticsearch before 72021-09-15

📋Vendor Advisories

1
Red Hat
elasticsearch: document and field level security was not applied to searchable snapshots2021-08-03
CVE-2021-22147 — Incorrect Permission Assignment | cvebase