Unrated severityNVD Advisory· Published Jul 21, 2021· Updated Aug 3, 2024
CVE-2021-22146
CVE-2021-22146
Description
All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the default setting the anonymous user has no permissions and is unable to successfully query any Elasticsearch APIs, an attacker could leverage the anonymous user to gain insight into certain details of a deployed cluster.
Affected products
2- Elastic/Elastic Cloud Enterprisedescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- packetstormsecurity.com/files/163655/Elasticsearch-ECE-7.13.3-Database-Disclosure.htmlmitrex_refsource_MISC
- discuss.elastic.co/t/elastic-cloud-enterprise-security-update/279180mitrex_refsource_MISC
- security.netapp.com/advisory/ntap-20210819-0005/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.