CVE-2020-7009: High severity Elastic Elasticsearch vulnerability
Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API key being generated with elevated privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Elasticsearchto a version that resolves this vulnerability.Fixed in 6.8.8 - Upgrade
Upgrade
Elasticsearchto a version that resolves this vulnerability.Fixed in 7.6.2
Event History
Frequently Asked Questions
What is the vulnerability identifier for this flaw?
The vulnerability identifier for this flaw is CVE-2020-7009.
What is the severity of CVE-2020-7009?
The severity of CVE-2020-7009 is high with a CVSS score of 8.8.
Which versions of Elasticsearch are affected by CVE-2020-7009?
Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 are affected by CVE-2020-7009.
What is the impact of CVE-2020-7009?
An attacker with the ability to create API keys can exploit this vulnerability to perform privilege escalation.
Where can I find more information about CVE-2020-7009?
More information about CVE-2020-7009 can be found at the following references: 1. https://discuss.elastic.co/t/elastic-stack-6-8-8-and-7-6-2-security-update/225920 2. https://security.netapp.com/advisory/ntap-20200403-0004/ 3. https://www.elastic.co/community/security/