Elasticsearch是荷兰Elasticsearch公司的一套基于Lucene构建的开源分布式RESTful搜索引擎。该产品主要应用于云计算,并支持通过HTTP使用JSON进行数据索引。 Elasticsearch 存在信息泄露漏洞,攻击者可利用该漏洞通过Suggester/Profile API绕过数据访问限制,以获取敏感信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Elastic | Elasticsearch | before 7.11.2 and 6.8.15 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-22140 | Elastic App Search web crawler 代码问题漏洞 | |
| CVE-2021-22138 | Elasticsearch Logstash 信任管理问题漏洞 | |
| CVE-2021-22139 | Elastic Stack Kibana 资源管理错误漏洞 | |
| CVE-2021-22137 | Elasticsearch 信息泄露漏洞 | |
| CVE-2021-22136 | Elastic Stack Kibana 代码问题漏洞 |
No comments yet