S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-22145 Scanner

CVE-2021-22145 scanner - Memory Disclosure vulnerability in Elasticsearch

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-22145
6.5
CVSS

A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer. This buffer could contain sensitive information such as Elasticsearch documents or authentication details.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Elasticsearchby Elastic
7.10.0
Updated Aug 21, 2026View on NVD →
Detail

Elasticsearch is a popular search and analytics engine used for indexing and searching large volumes of structured and unstructured data. It is commonly integrated into various software applications and web services for efficient and scalable data processing.

Recently, a serious memory disclosure vulnerability has been discovered in Elasticsearch versions 7.10.0 to 7.13.3. This vulnerability, identified as CVE-2021-22145, allows an attacker with the ability to submit arbitrary queries to Elasticsearch to exploit a malformed query that results in an error message containing previously used portions of a data buffer. This buffer could contain sensitive information, including Elasticsearch documents or authentication details.

When exploited, the CVE-2021-22145 vulnerability can lead to significant security concerns as the attackers can gain access to sensitive data and perform malicious activities such as unauthorized access, data theft, and data manipulation. Since Elasticsearch is widely used for processing sensitive data such as financial records, personally identifiable information, and intellectual property data, this vulnerability can have far-reaching implications.

s4e.io offers pro features that enable users to quickly and easily identify and address vulnerabilities in their digital assets. By leveraging this platform, users can stay updated on the latest vulnerabilities and security threats and take actionable steps to secure their data and applications. With the heightened threat landscape and the risks posed by cybersecurity attacks, it is essential to remain vigilant and proactive in protecting sensitive information and digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users are advised to take the following precautions:

  • Upgrade to the latest Elasticsearch version that includes a fix for this vulnerability.
  • Restrict network access to Elasticsearch instances to trusted hosts only.
  • Implement access control measures that restrict unauthorized access to Elasticsearch.
  • Regularly monitor Elasticsearch instances for any anomalous activities or suspicious requests.
  • Monitor Elasticsearch logs for any error messages that may contain sensitive information.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.