#VU51710 Security restrictions bypass in Elasticsearch - CVE-2021-22135
Published: March 25, 2021
Elasticsearch
Elastic Stack
Description
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists in the Elasticsearch suggester and profile API when Document and Field Level Security are enabled. A remote user can perform certain queries to enable the profiler and suggester on index and disclose existence of documents and fields.