GHSA-q394-h7f5-7f44 · Severity: medium · Ecosystem: maven — Generation of Error Message Containing Sensitive Information in Elasticsearch
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer. This buffer could contain sensitive information such as Elasticsearch documents or authentication details.
Conclusion & alert: CVE-2021-22145 is rated High Exploit Risk (77.7/100): CVSS Medium severity, with high exploitation likelihood (EPSS 67.93%, 99th percentile). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +2.23% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 50149 | exploit_db | edb | 2021-07-23 | Exploit-DB ↗ |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-01-18 | 65.70% | 67.93% | +2.23% |
| 2 | 2025-12-28 | 64.85% | 65.70% | +0.84% |
| 3 | 2025-12-27 | — | 64.85% | — |
Full EPSS history (62 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.5 | 3.1 | MEDIUM |
|
2.8 | 3.6 | [email protected] |
| 4.0 | 2.0 | MEDIUM |
|
8.0 | 2.9 | [email protected] |
GHSA-q394-h7f5-7f44 · Severity: medium · Ecosystem: maven — Generation of Error Message Containing Sensitive Information in Elasticsearch
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2021-22145 |
suse
|
high | CVE-2021-22145 severity important: SUSE including 1 source package names (elasticsearch), 6 product×package rows across 6 product lines (HPE Helion OpenStack 8, SUSE OpenStack Cloud 7, … (6 product lines)): Known Not Affected 6. | https://www.suse.com/security/cve/CVE-2021-22145/ |
ubuntu
|
medium | CVE-2021-22145 medium priority: Ubuntu including 1 source packages (elasticsearch), 9 status rows across 9 suites (focal, jammy, mantic, noble, oracular, plucky, questing, upstream, xenial): DNE 7, needs-triage 2. | https://ubuntu.com/security/CVE-2021-22145 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| elastic | elasticsearch | >= 7.10.0, <= 7.13.3 | cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:* |
| oracle | communications_cloud_native_core_automated_test_suite | 1.8.0 | cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.8.0:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://packetstormsecurity.com/files/163648/ElasticSearch-7.13.3-Memory-Disclosure.html | Exploit Third Party Advisory VDB Entry |
| https://discuss.elastic.co/t/elasticsearch-7-13-4-security-update/279177 | Vendor Advisory |
| https://gist.github.com/lucasdrufva/f9c5d7c9e26ee087b736d727953afd34 | |
| https://security.netapp.com/advisory/ntap-20210827-0006/ | Third Party Advisory |
| https://www.oracle.com/security-alerts/cpuapr2022.html | Patch Third Party Advisory |