HIGH 8.8 Maven
Improper Privilege Management in Elasticsearch
GHSA-gfv5-grx2-9jw2 · BIT-elasticsearch-2020-7009 · CVE-2020-7009
Published · Modified
Description
Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API key being generated with elevated privileges.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes