#VU67519 Out-of-bounds read in Elasticsearch - CVE-2021-22145
Published: September 21, 2022 / Updated: September 7, 2023
Elasticsearch
Elastic Stack
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists in Elasticsearch error reporting. A remote attacker can submit a malformed query that would result in an error message returned containing previously used portions of a data buffer with sensitive information such as Elasticsearch documents or authentication details.
Remediation
External links
- https://discuss.elastic.co/t/elasticsearch-7-13-4-security-update/279177
- http://packetstormsecurity.com/files/163648/ElasticSearch-7.13.3-Memory-Disclosure.html
- https://security.netapp.com/advisory/ntap-20210827-0006/
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1985039