CVE-2021-22132
Summary
| CVE | CVE-2021-22132 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-14 20:15:00 UTC |
| Updated | 2022-05-12 14:52:00 UTC |
| Description | Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This issue is fixed in Elasticsearch 7.10.2 |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Elasticsearch 7.10.2 Security Update - Security Announcements - Discuss the Elastic Stack |
MISC |
discuss.elastic.co |
Release Notes, Vendor Advisory |
| Oracle Critical Patch Update Advisory - April 2022 |
MISC |
www.oracle.com |
|
| CVE-2021-22132 Elasticsearch Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982914 Java (maven) Security Update for org.elasticsearch:elasticsearch (GHSA-5fvx-2jj3-6mff)