CVE-2021-22145
Generation of Error Message Containing Sensitive Information in Elasticsearch
6.5
MEDIUM
CVSS 3.1
EPSS 67.9%
Description
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer. This buffer could contain sensitive information such as Elasticsearch documents or authentication details.
How to fix CVE-2021-22145
To remediate CVE-2021-22145, upgrade the affected package to a fixed version below.
- —upgrade to 7.13.4 or later
- —upgrade to 7.13.4 or later
Is CVE-2021-22145 being exploited?
Likely — EPSS is 67.9%, placing CVE-2021-22145 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (2)
- >= 7.10.0, < 7.13.4
- >= 7.10.0, < 7.13.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |