CVE-2021-22145
CVE-2021-22145 is a medium-severity vulnerability in Elastic Elasticsearch with a CVSS 3.x base score of 6.5. Its EPSS exploit-prediction score of 76% places it in the 100th percentile, indicating an elevated likelihood of exploitation. The underlying weakness is classified as CWE-209.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- CVSS v2: 4.0
- EPSS exploit prediction: 76% (100th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-209
- Affected product: Elastic Elasticsearch
- Published:
- Last modified:
Description
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer. This buffer could contain sensitive information such as Elasticsearch documents or authentication details.
Frequently asked questions
- What is CVE-2021-22145?
- A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer. This buffer could contain sensitive information such as Elasticsearch documents or authentication details.
- How severe is CVE-2021-22145?
- CVE-2021-22145 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2021-22145 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 76% (100th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2021-22145?
- CVE-2021-22145 primarily affects Elastic Elasticsearch. In total, 2 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2021-22145?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2021-22145 published?
- CVE-2021-22145 was published on 2021-07-21 and last updated on 2026-06-17.
References
- http://packetstormsecurity.com/files/163648/ElasticSearch-7.13.3-Memory-Disclosure.html
- https://discuss.elastic.co/t/elasticsearch-7-13-4-security-update/279177
- https://gist.github.com/lucasdrufva/f9c5d7c9e26ee087b736d727953afd34
- https://security.netapp.com/advisory/ntap-20210827-0006/
- https://www.oracle.com/security-alerts/cpuapr2022.html
Affected products (2)
- cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.8.0:*:*:*:*:*:*:*
More vulnerabilities in Elastic Elasticsearch
- CVE-2015-5377 — Critical (CVSS 9.8): Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the…
- CVE-2015-1427 — Critical (CVSS 9.8): The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the…
- CVE-2026-72649 — High (CVSS 8.8): Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code…
- CVE-2026-72642 — High (CVSS 8.8): The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model…
- CVE-2020-7014 — High (CVSS 8.8): The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1…
- CVE-2020-7009 — High (CVSS 8.8): Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an…
All CVEs affecting Elastic Elasticsearch →
Other CWE-209 (Generation of Error Message Containing Sensitive Information) vulnerabilities
- CVE-2025-62168 — Critical (CVSS 10.0): Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication…
- CVE-2025-68110 — Critical (CVSS 9.9): ChurchCRM is an open-source church management system. Versions prior to 6.5.3 may disclose database information in an…
- CVE-2025-46658 — Critical (CVSS 9.8): An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. There are verbose error messages.
- CVE-2024-28285 — Critical (CVSS 9.8): A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows…
- CVE-2023-40767 — Critical (CVSS 9.8): User enumeration is found in in PHPJabbers Make an Offer Widget v1.0. This issue occurs during password recovery, where…
- CVE-2023-40766 — Critical (CVSS 9.8): User enumeration is found in in PHPJabbers Ticket Support Script v3.2. This issue occurs during password recovery,…
Browse all CWE-209 (Generation of Error Message Containing Sensitive Information) vulnerabilities →
Threat intelligence
Threat-intel indicators referencing this CVE:
- 129.204.154.232 (ipv4-addr)
- 150.158.196.236 (ipv4-addr)