Vulnerability record · CVE-2021-22145 · published 21 July 2021
CVE-2021-22145: Elasticsearch error reporting memory disclosure leaks buffer contents
Elastic · Elasticsearch
Elasticsearch 7.10.0 through 7.13.3 returns error messages for malformed queries that include previously used portions of a data buffer. That buffer can hold sensitive content such as Elasticsearch documents or authentication details, so an error path becomes an information leak.
Description
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer. This buffer could contain sensitive information such as Elasticsearch documents or authentication details.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityThe flaw is remotely reachable with low privileges, leaks sensitive data, has a public exploit reference and a very high EPSS score, though it is not in KEV.
What it is
Elasticsearch 7.10.0 through 7.13.3 returns error messages for malformed queries that include previously used portions of a data buffer. That buffer can hold sensitive content such as Elasticsearch documents or authentication details, so an error path becomes an information leak.
Impact
An attacker who can submit queries gains read access to memory-resident data, potentially including indexed documents and authentication details, without modifying or disrupting the service.
Attack surface
Reached over the network by submitting a malformed query to Elasticsearch; the CVSS vector requires low privileges (PR:L) and no user interaction. Any account able to send arbitrary queries is sufficient.
Exploitation
Not listed in CISA KEV, but EPSS is 0.76249 (99.51st percentile) and a public Packet Storm exploit reference exists, indicating high likelihood and available proof-of-concept code.
What to do
- Upgrade Elasticsearch to 7.13.4 or later, which the vendor advisory identifies as the fixed release.
- Apply the Oracle CPU April 2022 updates for affected Oracle products that bundle Elasticsearch.
- Restrict query submission to trusted, authenticated users and remove anonymous or overly broad read access.
- Review and sanitize error responses returned to clients so internal buffer content is not exposed.
Detection
- Monitor Elasticsearch logs for repeated malformed-query errors and error responses containing unexpected binary or document-like content.
- Alert on anomalous query patterns from a single account, especially bursts of deliberately invalid queries.
- Inspect outbound error payloads for strings resembling credentials, tokens or indexed document fields.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/163648/ElasticSearch-7.13.3-Memory-Disclosure.html | ExploitThird Party AdvisoryVDB Entry |
| https://discuss.elastic.co/t/elasticsearch-7-13-4-security-update/279177 | Vendor Advisory |
| https://gist.github.com/lucasdrufva/f9c5d7c9e26ee087b736d727953afd34 | |
| https://security.netapp.com/advisory/ntap-20210827-0006/ | Third Party Advisory |
| https://www.oracle.com/security-alerts/cpuapr2022.html | PatchThird Party Advisory |
| http://packetstormsecurity.com/files/163648/ElasticSearch-7.13.3-Memory-Disclosure.html | ExploitThird Party AdvisoryVDB Entry |
| https://discuss.elastic.co/t/elasticsearch-7-13-4-security-update/279177 | Vendor Advisory |
| https://security.netapp.com/advisory/ntap-20210827-0006/ | Third Party Advisory |
| https://www.oracle.com/security-alerts/cpuapr2022.html | PatchThird Party Advisory |
Track CVE-2021-22145 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-22145), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.