Security

Volver a Security Alert

Elasticsearch and Liferay Enterprise Search Security Advisory: January 15, 2021

The following issues may affect the functionality of your Liferay DXP and Enterprise Search environment. This notification provides a description of the latest compatibility change and required actions for Liferay Enterprise Search Subscribers.

Deployments which might be impacted

  • Liferay DXP 7.3 on Elastic Stack 7.9.x and before 7.10.2
  • Liferay DXP 7.2 on Elastic Stack 7.7.x and before 7.10.2

Vulnerability Information

Elasticsearch authorization-header storage issue (ESA-2021-01)

An information disclosure flaw was found in the Elasticsearch async search API. Users who execute an async search will store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster.

Affected Versions:

All Elasticsearch versions starting with 7.7.0 and before 7.10.2

Solutions and Mitigations:

Users should upgrade to Elasticsearch 7.10.2. There is no known workaround for this issue.

CVSSv3: 4.8 - AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N

CVE ID: CVE-2021-22132

Additional Information

Liferay's Elasticsearch connectors and out-of-the-box features are not using the Async Search APIs of Elasticsearch. In addition, communication between Liferay DXP and the Elasticsearch nodes happens through the Transport layer, not over HTTP in DXP 7.2 and prior versions. Please refer to this article for a technical overview of the Elasticsearch connectors available for Liferay DXP.

Search Engine Compatibility Matrix

Reference the information here for the detailed Elasticsearch compatibility including the compatible connector versions and required patch levels.

Vendor References


Elastic, Elasticsearch, and X-Pack are trademarks of Elasticsearch BV, registered in the U.S. and in other countries.

On this page