First published: Tue Mar 31 2020(Updated: )
Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API key being generated with elevated privileges.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic | >=6.7.0<6.8.8 | |
Elastic | >=7.0.0<7.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability identifier for this flaw is CVE-2020-7009.
The severity of CVE-2020-7009 is high with a CVSS score of 8.8.
Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 are affected by CVE-2020-7009.
An attacker with the ability to create API keys can exploit this vulnerability to perform privilege escalation.
More information about CVE-2020-7009 can be found at the following references: 1. https://discuss.elastic.co/t/elastic-stack-6-8-8-and-7-6-2-security-update/225920 2. https://security.netapp.com/advisory/ntap-20200403-0004/ 3. https://www.elastic.co/community/security/