tencent cloud

Elasticsearch Service

User Guide
Release Notes and Announcements
Release Notes
Product Announcements
Security Announcement
Product Introduction
Overview
Elasticsearch Version Support Notes
Features
Elastic Stack (X-Pack)
Strengths
Scenarios
Capabilities and Restrictions
Related Concepts
Purchase Guide
Billing Overview
Pricing
Elasticsearch Service Serverless Pricing
Notes on Arrears
ES Kernel Enhancement
Kernel Release Notes
Targeted Routing Optimization
Compression Algorithm Optimization
FST Off-Heap Memory Optimization
Getting Started
Evaluation of Cluster Specification and Capacity Configuration
Creating Clusters
Accessing Clusters
ES Serverless Guide
Service Overview
Basic Concepts
5-Minute Quick Experience
Quick Start
Access Control
Writing Data
Data Query
Index Management
Alarm Management
ES API References
Related Issues
Data Application Guide
Data Application Overview
Data Management
Elasticsearch Guide
Managing Clusters
Access Control
Multi-AZ Cluster Deployment
Cluster Scaling
Cluster Configuration
Plugin Configuration
Monitoring and Alarming
Log Query
Data Backup
Upgrade
Practical Tutorial
Data Migration and Sync
Use Case Construction
Index Configuration
SQL Support
Receiving Watcher Alerts via WeCom Bot
API Documentation
History
Introduction
API Category
Instance APIs
Making API Requests
Data Types
Error Codes
FAQs
Product
ES Cluster
Service Level Agreement
Glossary
New Version Introduction
Elasticsearch Service July 2020 Release
Elasticsearch Service February 2020 Release
Elasticsearch Service December 2019 Release

Notice for CVE-2021-22145 Vulnerability

PDF
フォーカスモード
フォントサイズ
最終更新日: 2025-02-20 17:26:43

Vulnerability Description

Tencent Cloud Elasticsearch Service (ES) version 7.10.1 is affected by the CVE-2021-22145 vulnerability. A user with permission to submit arbitrary queries to Elasticsearch may submit malformed queries, which result in error messages returned containing previously used portions of data buffers. These buffers may contain sensitive information, such as Elasticsearch documents or authentication details, causing possible information leakage. If authentication information for high-privilege accounts is obtained by hackers, they can achieve permission escalation. For the details about the vulnerability, see NVD - cve-2021-22145.

Impact

Tencent Cloud ES clusters of Elasticsearch version 7.10.1 (including Platinum and Basic Editions) are affected by this vulnerability. Users of affected clusters may follow the instructions below to perform remediation.

Solution

Upgrade the Elasticsearch version of your ES clusters to 7.14.2 or higher in the ES console. Before upgrading, follow the instructions in the console to perform relevant checks and select the appropriate upgrade method. For the operation instructions, see Upgrading ES Clusters.

Alternatively, you can prevent related risks through access control management, if you do not want to upgrade the clusters at the moment.
For the clusters that do not need public network access, disable the public network access. Clusters with public network access disabled can only be accessed within the VPC, which effectively ensures the security of query submissions.
For the clusters that need public network access, configure a public network access policy to control the allowlist IP addresses and ensure that only trusted IP addresses can access the ES clusters.


ヘルプとサポート

この記事はお役に立ちましたか?

フィードバック