Record summary

CVE-2021-22146 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the default setting the anonymous user has no permissions and is unable to successfully query any Elasticsearch APIs, an attacker could leverage the anonymous user to gain insight into certain details of a deployed cluster.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

Proofs of concept

2

Catalogued exploits

ExploitDBElasticsearch ECE 7.13.3 - Anonymous Database DumpExploitDB exploitby Joan MartinezNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubmagichk/cve-2021-22146Repository PoCby magichkStars: 3Not analyzed2 files

2.3 KiB

GitHub

PoC details

References

4