QID 730234
Date Published: 2021-10-14
QID 730234: Elasticsearch Memory Disclosure Vulnerability (ESA-2021-16)
Elasticsearch is a search server based on Lucene that provides a distributed, multitenant-capable full-text search engine with an HTTP web interface and schema-free JSON documents.
Affected with following vulnerability:
CVE-2021-22145: A memory disclosure vulnerability was identified in Elasticsearch's error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer. This buffer could contain sensitive information such as Elasticsearch documents or authentication details.
Affected Versions:
Elasticsearch versions prior to 7.13.4
QID detection logic:
Checks the vulnerable versions of ElasticSearch.
Successful exploitation of this vulnerability may allow an attacker to affect the confidentiality of the targeted user.
- ESA-2021-16 -
www.elastic.co/community/security/
CVEs related to QID 730234
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ESA-2021-16 |
|