CVE-2021-22145 is a medium-severity memory disclosure vulnerability affecting Elasticsearch versions 7.10.0 through 7.13.3, as well as related Oracle and Elastic Cloud Native Core products. An authenticated attacker can submit a specially crafted, malformed query to Elasticsearch, causing error messages to inadvertently reveal portions of a data buffer. This buffer could contain sensitive information such as Elasticsearch documents or authentication details, leading to a high impact on confidentiality. While not on CISA's KEV list, public exploit code exists in Metasploit and ExploitDB, and Nuclei templates are available, indicating readily accessible exploitation tools. Despite this, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.10.0, <= 7.13.3CPE match | cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.