packetstormsecurity.com
http://packetstormsecurity.com/files/163655/Elasticsearch-ECE-7.13.3-Database-Disclosure.html CVE-2021-22146
HIGH
Elasticsearch ECE 7.13.3 - Anonymous Database Dump
Record summary
CVE-2021-22146 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the default setting the anonymous user has no permissions and is unable to successfully query any Elasticsearch APIs, an attacker could leverage the anonymous user to gain insight into certain details of a deployed cluster.
Description source: CVE List
Exploitation context
Proofs of concept
2Catalogued exploits
ExploitDBElasticsearch ECE 7.13.3 - Anonymous Database DumpExploitDB exploitby Joan MartinezNot analyzed1 file
Repository PoCs
GitHubmagichk/cve-2021-22146Repository PoCby magichkStars: 3Not analyzed2 files
References
4discuss.elastic.co
https://discuss.elastic.co/t/elastic-cloud-enterprise-security-update/279180 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-22146 security.netapp.comConfirmation
https://security.netapp.com/advisory/ntap-20210819-0005