Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-22135
HistoryMay 13, 2021 - 12:00 a.m.

CVE-2021-22135

2021-05-1300:00:00
ubuntu.com
ubuntu.com
11
elasticsearch
document disclosure
suggester and profile api
security flaw
field level security

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

38.7%

Elasticsearch versions before 7.11.2 and 6.8.15 contain a document
disclosure flaw was found in the Elasticsearch suggester and profile API
when Document and Field Level Security are enabled. The suggester and
profile API are normally disabled for an index when document level security
is enabled on the index. Certain queries are able to enable the profiler
and suggester which could lead to disclosing the existence of documents and
fields the attacker should not be able to view.

OSVersionArchitecturePackageVersionFilename
ubuntu16.04noarchelasticsearch< anyUNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

38.7%