Security restrictions bypass in Elasticsearch - CVE-2021-22135
Published: March 25, 2021
Vulnerability details
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists in the Elasticsearch suggester and profile API when Document and Field Level Security are enabled. A remote user can perform certain queries to enable the profiler and suggester on index and disclose existence of documents and fields.
Affected software
Red Hat Integration Camel Extensions for Quarkus
IBM Security SOAR
Junos Space Security Director
How to mitigate CVE-2021-22135
IBM Security SOAR - update to 42.0.7058
Junos Space Security Director - update to 24.1R3