Meet Corgea at Black Hat, BSides Las Vegas & DEF CON
HIGH 8.8 Maven

Improper Privilege Management in Elasticsearch

GHSA-gfv5-grx2-9jw2 · BIT-elasticsearch-2020-7009 · CVE-2020-7009

Published · Modified

Description

Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API key being generated with elevated privileges.

Ready to move

Start Securing

Free, no credit card | First findings in minutes