An information disclosure via GET request server-side request forgery vulnerability was discovered with the Workplace Search Github Enterprise Server integration. Using this vulnerability, a malicious Workplace Search admin could use the GHES integration to view hosts that might not be publicly accessible.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-24415 An information disclosure via GET request server-side request forgery vulnerability was discovered with the Workplace Search Github Enterprise Server integration. Using this vulnerability, a malicious Workplace Search admin could use the GHES integration to view hosts that might not be publicly accessible.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2024-08-04T01:30:08.972Z

Reserved: 2021-08-03T00:00:00

Link: CVE-2021-37940

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-12-07T19:15:07.493

Modified: 2024-11-21T06:16:06.910

Link: CVE-2021-37940

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.