6.5
CVSSv3

CVE-2021-22145

Published: 21/07/2021 Updated: 10/05/2022
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer. This buffer could contain sensitive information such as Elasticsearch documents or authentication details.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

elastic elasticsearch

oracle communications cloud native core automated test suite 1.8.0

Vendor Advisories

A memory disclosure vulnerability was identified in Elasticsearch 7100 to 7133 error reporting A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer This buffer could contain sensitive information s ...
A memory disclosure vulnerability was identified in Elasticsearch’s error reporting in versions 7100 up to 7133 A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer This buffer could contain sens ...

Exploits

ElasticSearch version 7133 memory disclosure exploit ...

Github Repositories