CVE-2021-31828
Summary
| CVE | CVE-2021-31828 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-06 19:15:00 UTC |
| Updated | 2021-05-18 13:26:00 UTC |
| Description | An SSRF issue in Open Distro for Elasticsearch (ODFE) before 1.13.1.0 allows an existing privileged user to enumerate listening services or interact with configured resources via HTTP requests exceeding the Alerting plugin's intended scope. |
Risk And Classification
Problem Types: CWE-918
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Amazon | Open Distro | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Support host deny list for Destinations by skkosuri-amzn · Pull Request #353 · opendistro-for-elasticsearch/alerting · GitHub | CONFIRM | github.com | |
| Version History - Open Distro for Elasticsearch Documentation | MISC | opendistro.github.io | |
| CVE-2021-31828 - SSRF in Open Distro for ElasticSearch | MISC | rotem-bar.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.