XML External Entity injection in App Search web crawler - CVE-2021-22140
Published: April 28, 2021
App Search web crawler
Elastic Stack
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied XML input in Enterprise Search. A remote attacker whose website is being crawled by App Search can craft a malicious sitemap.xml to traverse the filesystem of the host running the instance and obtain sensitive files.