An information disclosure via GET request server-side request forgery vulnerability was discovered with the Workplace Search Github Enterprise Server integration. Using this vulnerability, a malicious Workplace Search admin could use the GHES integration to view hosts that might not be publicly accessible.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published: 2021-12-07T18:59:29

Updated: 2024-08-04T01:30:08.972Z

Reserved: 2021-08-03T00:00:00

Link: CVE-2021-37940

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-12-07T19:15:07.493

Modified: 2021-12-09T19:24:52.917

Link: CVE-2021-37940

cve-icon Redhat

No data.