ZeroHour

CVE-2021-22147

CVSS 3.1
6.5 medium
EPSS
1%p62
Published
()
Modified
Description

Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.

Vendors
elastic
Products
elasticsearch
Weakness
CWE-732, CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.