Out-of-bounds read in Elasticsearch - CVE-2021-22145
Published: September 21, 2022 / Updated: September 7, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists in Elasticsearch error reporting. A remote attacker can submit a malformed query that would result in an error message returned containing previously used portions of a data buffer with sensitive information such as Elasticsearch documents or authentication details.
Affected software
Operations Dashboard
Netcool Operations Insight
How to mitigate CVE-2021-22145
Operations Dashboard - addressed in versions 2020.4.1-3, 2021.3.1
Netcool Operations Insight - update to 1.6.10
Links to Public Exploits and PoC-codes
External References
- https://discuss.elastic.co/t/elasticsearch-7-13-4-security-update/279177
- http://packetstormsecurity.com/files/163648/ElasticSearch-7.13.3-Memory-Disclosure.html
- https://security.netapp.com/advisory/ntap-20210827-0006/
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1985039