4
CVSSv2

CVE-2021-22147

Published: 15/09/2021 Updated: 04/11/2022
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Elasticsearch prior to 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

elastic elasticsearch

Vendor Advisories

A flaw was discovered in Elasticsearch versions 7110 to 7134 where document and field level security was not applied to searchable snapshots This could lead to an authenticated user gaining access to information that they are unauthorized to view ...