CVE-2021-22147
Summary
| CVE | CVE-2021-22147 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-15 12:15:00 UTC |
| Updated | 2022-11-04 18:27:00 UTC |
| Description | Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Elastic Stack 7.14.0 Security Update - Security Announcements - Discuss the Elastic Stack |
MISC |
discuss.elastic.co |
|
| Security issues | Elastic |
MISC |
www.elastic.co |
|
| CVE-2021-22147 Elasticsearch Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 730232 Elasticsearch Access Control Vulnerability (ESA-2021-18)
- 900440 Common Base Linux Mariner (CBL-Mariner) Security Update for rubygem-elasticsearch (6278)
- 980458 Java (maven) Security Update for org.elasticsearch:elasticsearch (GHSA-45h5-r968-5xr7)