Vulnerabilities > CVE-2021-22147 - Missing Authorization vulnerability in Elastic Elasticsearch

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
elastic
CWE-862

Summary

Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.

Common Weakness Enumeration (CWE)