CVE-2021-37940 is an information disclosure vulnerability affecting Elastic Enterprise Search, specifically its Workplace Search GitHub Enterprise Server integration. A highly privileged attacker (Workplace Search admin) could exploit this server-side request forgery (SSRF) vulnerability to access internal network hosts not publicly accessible. Rated as MEDIUM severity (CVSS 6.8), its impact is high confidentiality loss with no integrity or availability impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.16.0CPE matchmatch criteria | cpe:2.3:a:elastic:enterprise_search:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.