QID 730234

Date Published: 2021-10-14

QID 730234: Elasticsearch Memory Disclosure Vulnerability (ESA-2021-16)

Elasticsearch is a search server based on Lucene that provides a distributed, multitenant-capable full-text search engine with an HTTP web interface and schema-free JSON documents.

Affected with following vulnerability:
CVE-2021-22145: A memory disclosure vulnerability was identified in Elasticsearch's error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer. This buffer could contain sensitive information such as Elasticsearch documents or authentication details.

Affected Versions:
Elasticsearch versions prior to 7.13.4

QID detection logic:
Checks the vulnerable versions of ElasticSearch.

Successful exploitation of this vulnerability may allow an attacker to affect the confidentiality of the targeted user.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Customers are advised to upgrade to Elasticsearch version 7.13.4 to remediate this vulnerability.
    Vendor References

    CVEs related to QID 730234

    Software Advisories
    Advisory ID Software Component Link
    ESA-2021-16 URL Logo www.elastic.co/community/security/