{"api_version":"1","generated_at":"2026-07-24T00:04:15+00:00","cve":"CVE-2021-22132","urls":{"html":"https://cve.report/CVE-2021-22132","api":"https://cve.report/api/cve/CVE-2021-22132.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-22132","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-22132"},"summary":{"title":"CVE-2021-22132","description":"Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This issue is fixed in Elasticsearch 7.10.2","state":"PUBLIC","assigner":"security@elastic.co","published_at":"2021-01-14 20:15:00","updated_at":"2022-05-12 14:52:00"},"problem_types":["CWE-522"],"metrics":[],"references":[{"url":"https://discuss.elastic.co/t/elasticsearch-7-10-2-security-update/261164","name":"https://discuss.elastic.co/t/elasticsearch-7-10-2-security-update/261164","refsource":"MISC","tags":["Release Notes","Vendor Advisory"],"title":"Elasticsearch 7.10.2 Security Update - Security Announcements - Discuss the Elastic Stack","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","name":"https://www.oracle.com/security-alerts/cpuapr2022.html","refsource":"MISC","tags":[],"title":"Oracle Critical Patch Update Advisory - April 2022","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.netapp.com/advisory/ntap-20210219-0004/","name":"https://security.netapp.com/advisory/ntap-20210219-0004/","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"CVE-2021-22132 Elasticsearch Vulnerability in NetApp Products | NetApp Product Security","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-22132","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-22132","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"22132","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"elastic","cpe5":"elasticsearch","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"22132","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"elastic","cpe5":"elasticsearch","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"22132","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"communications_cloud_native_core_automated_test_suite","cpe6":"1.8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-22132","qid":"982914","title":"Java (maven) Security Update for org.elasticsearch:elasticsearch (GHSA-5fvx-2jj3-6mff)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ASSIGNER":"security@elastic.co","ID":"CVE-2021-22132","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Elastic","product":{"product_data":[{"product_name":"Elasticsearch","version":{"version_data":[{"version_value":"7.7.0 to 7.10.1"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-522: Insufficiently Protected Credentials"}]}]},"references":{"reference_data":[{"url":"https://discuss.elastic.co/t/elasticsearch-7-10-2-security-update/261164","refsource":"MISC","name":"https://discuss.elastic.co/t/elasticsearch-7-10-2-security-update/261164"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","refsource":"MISC","name":"https://www.oracle.com/security-alerts/cpuapr2022.html"},{"refsource":"CONFIRM","name":"https://security.netapp.com/advisory/ntap-20210219-0004/","url":"https://security.netapp.com/advisory/ntap-20210219-0004/"}]},"description":{"description_data":[{"lang":"eng","value":"Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This issue is fixed in Elasticsearch 7.10.2"}]}},"nvd":{"publishedDate":"2021-01-14 20:15:00","lastModifiedDate":"2022-05-12 14:52:00","problem_types":["CWE-522"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.2,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:H/Au:S/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":2.1},"severity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*","versionStartIncluding":"7.7.0","versionEndExcluding":"7.10.2","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.8.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"22132","Ordinal":"196827","Title":"CVE-2021-22132","CVE":"CVE-2021-22132","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"22132","Ordinal":"1","NoteData":"Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This issue is fixed in Elasticsearch 7.10.2","Type":"Description","Title":null},{"CveYear":"2021","CveId":"22132","Ordinal":"2","NoteData":"2021-01-14","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"22132","Ordinal":"3","NoteData":"2021-02-19","Type":"Other","Title":"Modified"}]}}}