Medium severity6.8NVD Advisory· Published Dec 7, 2021· Updated Jun 17, 2026
CVE-2021-37940
CVE-2021-37940
Description
An information disclosure via GET request server-side request forgery vulnerability was discovered with the Workplace Search Github Enterprise Server integration. Using this vulnerability, a malicious Workplace Search admin could use the GHES integration to view hosts that might not be publicly accessible.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: before 7.16.0
Patches
Vulnerability mechanics
References
1- discuss.elastic.co/t/enterprise-search-7-16-0-security-update/291146nvdVendor Advisory
News mentions
0No linked articles in our index yet.