CVE-2021-37940
07.12.2021, 19:15
An information disclosure via GET request server-side request forgery vulnerability was discovered with the Workplace Search Github Enterprise Server integration. Using this vulnerability, a malicious Workplace Search admin could use the GHES integration to view hosts that might not be publicly accessible.
Vendor | Product | Version |
---|---|---|
elastic | enterprise_search | 𝑥 < 7.16.0 |
𝑥
= Vulnerable software versions