CVE Database
/

CVE-2021-22134

Back to search

CVE-2021-22134

Published: Mar 8, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query against a recently updated document. This affects documents that have been updated and not yet refreshed in the index. This could result in the search disclosing the existence of documents and fields the attacker should not be able to view.

VendorProductVersions

Elastic

Elasticsearch

affected
after 7.6.0 and before 7.11.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now