Back to search
CVE-2021-22145
Published: Jul 21, 2021
Modified: Jul 8, 2025
PUBLISHED
Description
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer. This buffer could contain sensitive information such as Elasticsearch documents or authentication details.
| Vendor | Product | Versions |
|---|---|---|
Elastic | Elasticsearch | affected 7.10.0 - <= 7.13.3 |
Weaknesses (CWE)
References
https://www.oracle.com/security-alerts/cpuapr2022.html
x_refsource_MISC
https://security.netapp.com/advisory/ntap-20210827-0006/
x_refsource_CONFIRM
https://gist.github.com/lucasdrufva/f9c5d7c9e26ee087b736d727953afd34
technical-description
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now