CyberRota Analysis
AI-GeneratedElasticsearch contains an incorrect authorization vulnerability that allows authenticated users with limited index privileges to exploit insufficient controls in the ingest simulation feature. This can lead to unauthorized access to sensitive data processed by ingest pipelines and retrieval of index mapping metadata for indices beyond their access rights. Organizations using Elasticsearch should prioritize addressing this vulnerability to mitigate potential data exposure risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient authorization controls in the ingest simulation feature. By targeting indices they are not authorized to access directly, the user can cause those indices' configured ingest pipelines to execute and return their output, potentially disclosing data processed or enriched by those pipelines. Additionally, the same feature can be used to retrieve index mapping metadata for indices the user are not authorized to access directly.
Related CVEs
Other vulnerabilities affecting the same vendor(s)