Vulnerability Details CVE-2021-22145
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer. This buffer could contain sensitive information such as Elasticsearch documents or authentication details.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.611
EPSS Ranking 98.2%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2021-22145
-
cpe:2.3:a:elastic:elasticsearch:7.10.0
-
cpe:2.3:a:elastic:elasticsearch:7.10.1
-
cpe:2.3:a:elastic:elasticsearch:7.10.2
-
cpe:2.3:a:elastic:elasticsearch:7.11.0
-
cpe:2.3:a:elastic:elasticsearch:7.11.1
-
cpe:2.3:a:elastic:elasticsearch:7.11.2
-
cpe:2.3:a:elastic:elasticsearch:7.12.0
-
cpe:2.3:a:elastic:elasticsearch:7.12.1
-
cpe:2.3:a:elastic:elasticsearch:7.13.0
-
cpe:2.3:a:elastic:elasticsearch:7.13.1
-
cpe:2.3:a:elastic:elasticsearch:7.13.2
-
cpe:2.3:a:elastic:elasticsearch:7.13.3
-
cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.8.0