GHSA-5fvx-2jj3-6mff
Dashboard / Vulnerabilities / GHSA-5fvx-2jj3-6mff
GHSA-5fvx-2jj3-6mff
Summary: Insufficiently Protected Credentials in Elasticsearch
Details: Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This issue is fixed in Elasticsearch 7.10.2
References: https://nvd.nist.gov/vuln/detail/CVE-2021-22132, https://discuss.elastic.co/t/elasticsearch-7-10-2-security-update/261164, https://security.netapp.com/advisory/ntap-20210219-0004, https://www.oracle.com/security-alerts/cpuapr2022.html
Affected packages
Package
Name: org.elasticsearch:elasticsearch
Purl: pkg:maven/org.elasticsearch/elasticsearch
Affected ranges
Type: ECOSYSTEM
Events:
