<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 15:37:16 +0000</lastBuildDate>
    <item>
      <title>BIT-elasticsearch-2021-22135</title>
      <link>https://cve.radiocsirt.org/vuln/bit-elasticsearch-2021-22135</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: elasticsearch&lt;/p&gt;
&lt;p&gt;Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API when Document and Field Level Security are enabled. The suggester and profile API are normally disabled for an index when document level security is enabled on the index. Certain queries are able to enable the profiler and suggester which could lead to disclosing the existence of documents and fields the attacker should not be able to view.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: elasticsearch&lt;/p&gt;
&lt;p&gt;Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API when Document and Field Level Security are enabled. The suggester and profile API are normally disabled for an index when document level security is enabled on the index. Certain queries are able to enable the profiler and suggester which could lead to disclosing the existence of documents and fields the attacker should not be able to view.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-elasticsearch-2021-22135</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0304 — De multiples vulnérabilités ont été découvertes dans les produits Juniper Networks. Certaines d'entre elles permettent…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0304</link>
      <description>certfr-2025-avi-0304</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0304</guid>
    </item>
    <item>
      <title>EUVD-2026-22672</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-22672</link>
      <description>EUVD-2026-22672</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-22672</guid>
    </item>
    <item>
      <title>fkie_cve-2021-22135</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-22135</link>
      <description>&lt;p&gt;Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API when Document and Field Level Security are enabled. The suggester and profile API are normally disabled for an index when document level security is enabled on the index. Certain queries are able to enable the profiler and suggester which could lead to disclosing the existence of documents and fields the attacker should not be able to view.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API when Document and Field Level Security are enabled. The suggester and profile API are normally disabled for an index when document level security is enabled on the index. Certain queries are able to enable the profiler and suggester which could lead to disclosing the existence of documents and fields the attacker should not be able to view.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-22135</guid>
    </item>
    <item>
      <title>GHSA-62ww-4p3p-7fhj — API information disclosure flaw in Elasticsearch</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-62ww-4p3p-7fhj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.elasticsearch:elasticsearch&lt;/p&gt;
&lt;p&gt;Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API when Document and Field Level Security are enabled. The suggester and profile API are normally disabled for an index when document level security is enabled on the index. Certain queries are able to enable the profiler and suggester which could lead to disclosing the existence of documents and fields the attacker should not be able to view.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.elasticsearch:elasticsearch&lt;/p&gt;
&lt;p&gt;Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API when Document and Field Level Security are enabled. The suggester and profile API are normally disabled for an index when document level security is enabled on the index. Certain queries are able to enable the profiler and suggester which could lead to disclosing the existence of documents and fields the attacker should not be able to view.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-62ww-4p3p-7fhj</guid>
    </item>
    <item>
      <title>gsd-2021-22135</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-22135</link>
      <description>gsd-2021-22135</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-22135</guid>
    </item>
    <item>
      <title>RHSA-2022:5606 — Red Hat Security Advisory: Red Hat Integration Camel Extensions for Quarkus 2.7 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:5606</link>
      <description>&lt;p&gt;hadoop: WebHDFS client might send SPNEGO authorization header lz4: memory corruption due to an integer overflow bug caused by memmove argument elasticsearch: executing async search improperly stores HTTP headers leading to information disclosure elasticsearch: Document disclosure flaw in the Elasticsearch suggester elasticsearch: Document disclosure flaw when Document or Field Level Security is used jsoup: Crafted input may cause the jsoup HTML and XML parser to get stuck Kafka: Timing Attack Vulnerability for Apache Kafka Connect and Clients xstream: Injecting highly recursive collections or maps can cause a DoS quarkus: privilege escalation vulnerability with RestEasy Reactive scope leakage in Quarkus&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;hadoop: WebHDFS client might send SPNEGO authorization header lz4: memory corruption due to an integer overflow bug caused by memmove argument elasticsearch: executing async search improperly stores HTTP headers leading to information disclosure elasticsearch: Document disclosure flaw in the Elasticsearch suggester elasticsearch: Document disclosure flaw when Document or Field Level Security is used jsoup: Crafted input may cause the jsoup HTML and XML parser to get stuck Kafka: Timing Attack Vulnerability for Apache Kafka Connect and Clients xstream: Injecting highly recursive collections or maps can cause a DoS quarkus: privilege escalation vulnerability with RestEasy Reactive scope leakage in Quarkus&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:5606</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-22135</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-22135</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: elasticsearch&lt;/p&gt;
&lt;p&gt;Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API when Document and Field Level Security are enabled. The suggester and profile API are normally disabled for an index when document level security is enabled on the index. Certain queries are able to enable the profiler and suggester which could lead to disclosing the existence of documents and fields the attacker should not be able to view.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: elasticsearch&lt;/p&gt;
&lt;p&gt;Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API when Document and Field Level Security are enabled. The suggester and profile API are normally disabled for an index when document level security is enabled on the index. Certain queries are able to enable the profiler and suggester which could lead to disclosing the existence of documents and fields the attacker should not be able to view.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-22135</guid>
    </item>
  </channel>
</rss>
