漏洞描述 Elasticsearch7.10中发现了内存泄漏漏洞。7.10至7.13.3错误报告。能够向Elasticsearch提交任意查询的用户可能会提交格式不正确的查询,这将导致返回包含以前使用的数据缓冲区部分的错误消息。此缓冲区可能包含敏感信息,如Elasticsearch文档或身份验证详细信息。
相关漏洞推荐 POC CVE-2014-3120: ElasticSearch v1.1.1/1.2 RCE POC CVE-2015-1427: ElasticSearch - Remote Code Execution POC CVE-2015-3337: Elasticsearch - Local File Inclusion POC CVE-2015-5531: ElasticSearch <1.6.1 - Local File Inclusion POC CVE-2021-22145: Elasticsearch 7.10.0-7.13.3 - Information Disclosure POC CVE-2014-3120: ElasticSearch v1.1.1/1.2 RCE POC CVE-2015-1427: ElasticSearch - Remote Code Execution POC CVE-2015-3337: Elasticsearch File Read POC CVE-2015-5531: Elasticsearch CVE-2015-5531 POC CVE-2021-22145: ElasticSearch 7.13.3 - Memory disclosure POC elasticsearch-unauth: ElasticSearch Information Disclosure POC elasticsearch-default-login: ElasticSearch - Default Login POC elasticsearch: ElasticSearch Information Disclosure