A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer. This buffer could contain sensitive information such as Elasticsearch documents or authentication details.
The product generates an error message that includes sensitive information about its environment, users, or associated data.
Link | Tags |
---|---|
https://www.oracle.com/security-alerts/cpuapr2022.html | third party advisory patch |
https://security.netapp.com/advisory/ntap-20210827-0006/ | third party advisory |
https://discuss.elastic.co/t/elasticsearch-7-13-4-security-update/279177 | vendor advisory |
http://packetstormsecurity.com/files/163648/ElasticSearch-7.13.3-Memory-Disclosure.html | third party advisory vdb entry exploit |