Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 765496 (CVE-2021-22132) - <app-misc/elasticsearch-7.10.2: information disclosure in search API (CVE-2021-22132)
Summary: <app-misc/elasticsearch-7.10.2: information disclosure in search API (CVE-202...
Status: RESOLVED FIXED
Alias: CVE-2021-22132
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://discuss.elastic.co/t/elastics...
Whiteboard: ~4 [noglsa]
Keywords: PullRequest
Depends on:
Blocks:
 
Reported: 2021-01-15 01:30 UTC by John Helmert III
Modified: 2021-01-21 23:24 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-01-15 01:30:28 UTC
CVE-2021-22132:

Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This issue is fixed in Elasticsearch 7.10.2


Please bump.
Comment 1 Larry the Git Cow gentoo-dev 2021-01-21 23:23:12 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=b9b2e6e23c3cf888715e54938307ebb6713ebaea

commit b9b2e6e23c3cf888715e54938307ebb6713ebaea
Author:     Tomáš Mózes <hydrapolic@gmail.com>
AuthorDate: 2021-01-15 16:26:24 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2021-01-21 23:22:55 +0000

    app-misc/elasticsearch: bump to 7.10.2, drop old
    
    Bug: https://bugs.gentoo.org/765496
    Signed-off-by: Tomáš Mózes <hydrapolic@gmail.com>
    Signed-off-by: Sam James <sam@gentoo.org>

 app-misc/elasticsearch/Manifest                                       | 4 ++--
 .../{elasticsearch-7.10.0.ebuild => elasticsearch-7.10.2.ebuild}      | 0
 2 files changed, 2 insertions(+), 2 deletions(-)
Comment 2 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-01-21 23:24:58 UTC
All done, thanks!