CVE-2021-22147
- EPSS 0.31%
- Veröffentlicht 15.09.2021 12:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:35
Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.
CVE-2021-22144
- EPSS 0.39%
- Veröffentlicht 26.07.2021 12:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:35
In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit arbitrary queries to Elasticse...
CVE-2021-22146
- EPSS 29.9%
- Veröffentlicht 21.07.2021 15:15:14
- Zuletzt bearbeitet 21.11.2024 05:49:35
All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the default setting the anonymous user has no permissions and is unable to successfully query any Elasticsearch APIs, an...
CVE-2021-22145
- EPSS 58.51%
- Veröffentlicht 21.07.2021 15:15:14
- Zuletzt bearbeitet 08.07.2025 11:15:23
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned con...
CVE-2021-22137
- EPSS 0.14%
- Veröffentlicht 13.05.2021 18:15:09
- Zuletzt bearbeitet 21.11.2024 05:49:34
In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosure flaw was found when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain cross-cluster search queries. T...
CVE-2021-22135
- EPSS 0.21%
- Veröffentlicht 13.05.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:34
Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API when Document and Field Level Security are enabled. The suggester and profile API are normally disabled for an...
CVE-2021-22134
- EPSS 0.23%
- Veröffentlicht 08.03.2021 21:15:16
- Zuletzt bearbeitet 21.11.2024 05:49:34
A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query against a recently updated docu...
CVE-2020-7021
- EPSS 0.41%
- Veröffentlicht 10.02.2021 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:36:30
Elasticsearch versions before 7.10.0 and 6.8.14 have an information disclosure issue when audit logging and the emit_request_body option is enabled. The Elasticsearch audit log could contain sensitive information such as password hashes or authentica...
CVE-2021-22132
- EPSS 0.41%
- Veröffentlicht 14.01.2021 20:15:13
- Zuletzt bearbeitet 21.11.2024 05:49:34
Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obt...
CVE-2020-7020
- EPSS 0.12%
- Veröffentlicht 22.10.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:36:30
Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain complex queries. This could result in...