CVE Database
/

CVE-2021-22132

Back to search

CVE-2021-22132

Published: Jan 14, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This issue is fixed in Elasticsearch 7.10.2

VendorProductVersions

Elastic

Elasticsearch

affected
7.7.0 to 7.10.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now