#VU51712 Improper Preservation of Permissions in Elasticsearch - CVE-2021-22137
Published: March 25, 2021 / Updated: October 19, 2022
Elasticsearch
Elastic Stack
Description
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to search queries do not properly preserve security permissions when executing certain cross-cluster search queries. A remote user can disclose existence of documents via search functionality, when Document or Field Level Security is used.