CyberRota Analysis
AI-GeneratedElasticsearch is vulnerable to an authorization bypass that allows users with access to a cross-cluster API key to craft requests that can access unauthorized indices, potentially leading to information disclosure of sensitive data and metadata. This flaw arises from improper validation of shard identifiers in cross-cluster search requests, enabling attackers to exploit the discrepancy between authorization checks and actual shard access. Organizations utilizing Elasticsearch, particularly those managing sensitive data across clusters, should prioritize patching this vulnerability to mitigate the risk of unauthorized data exposure.
Original NVD Description
Authorization Bypass Through User-Controlled Key (CWE-639) in Elasticsearch can lead to Information Disclosure via a specially crafted cross-cluster search request that references an unauthorized shard identifier. Elasticsearch contains an authorization bypass weakness in its handling of cross-cluster search requests made through the Remote Cluster Security (RCS) 2.0 model. An authorization check validates a request against one identifying attribute of the target shard, while a separate, independently-supplied identifying attribute in the same request determines which shard is actually accessed. A holder of a cross-cluster API key authorized for one index can craft a request whose two identifying attributes refer to different indices, causing the request to be authorized against an index they can access while actually operating against a different, unauthorized index. This can expose that index's document contents, field mappings, and other metadata, and in limited cases allows modification of retention-lease state on the unauthorized index.
Related CVEs
Other vulnerabilities affecting the same vendor(s)