Security restrictions bypass in Elasticsearch - CVE-2021-22135

 

Security restrictions bypass in Elasticsearch - CVE-2021-22135

Published: March 25, 2021


Vulnerability identifier: #VU51710
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22135
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to sensitive information.

The vulnerability exists in the Elasticsearch suggester and profile API when Document and Field Level Security are enabled. A remote user can perform certain queries to enable the profiler and suggester on index and disclose existence of documents and fields.


Affected software

Elasticsearch
Red Hat Integration Camel Extensions for Quarkus
IBM Security SOAR
Junos Space Security Director

How to mitigate CVE-2021-22135

Install updates from vendor's website.

Elasticsearch - addressed in versions 6.8.15, 7.11.2
IBM Security SOAR - update to 42.0.7058
Junos Space Security Director - update to 24.1R3

External References

Related Security Bulletins