Medium severity4.8NVD Advisory· Published Jan 14, 2021· Updated Jun 17, 2026
CVE-2021-22132
CVE-2021-22132
Description
Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This issue is fixed in Elasticsearch 7.10.2
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.elasticsearch:elasticsearchMaven | >= 7.7.0, < 7.10.2 | 7.10.2 |
Affected products
5cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*range: >=7.7.0,<7.10.2
- (no CPE)range: 7.7.0 to 7.10.1
- cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.8.0:*:*:*:*:*:*:*
- osv-coords2 versions
>= 7.7.0, < 7.10.2+ 1 more
- (no CPE)range: >= 7.7.0, < 7.10.2
- (no CPE)range: >= 7.7.0, < 7.10.2
Patches
Vulnerability mechanics
References
6- www.oracle.com/security-alerts/cpuapr2022.htmlnvdPatchThird Party AdvisoryWEB
- discuss.elastic.co/t/elasticsearch-7-10-2-security-update/261164nvdRelease NotesVendor AdvisoryWEB
- github.com/advisories/GHSA-5fvx-2jj3-6mffghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-22132ghsaADVISORY
- security.netapp.com/advisory/ntap-20210219-0004/nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20210219-0004ghsaWEB
News mentions
0No linked articles in our index yet.