5
CVSSv2

CVE-2021-22140

Published: 13/05/2021 Updated: 21/05/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Elastic App Search versions after 7.11.0 and prior to 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta feature. Using this vector, an attacker whose website is being crawled by App Search could craft a malicious sitemap.xml to traverse the filesystem of the host running the instance and obtain sensitive files.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

Vendor Advisories

No description is available for this CVE ...
An XML External Entity Injection issue (XXE) was found in the App Search web crawler beta feature Using this vector, an attacker whose website is being crawled by App Search could craft a malicious sitemapxml to traverse the filesystem of the host running the instance and obtain sensitive files ...