CVE-2020-7014: High severity elastic vulnerability
The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication tokens. An attacker who is able to generate an API key and an authentication token can perform a series of steps that result in an authentication token being generated with elevated privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7014?
CVE-2020-7014 is a privilege escalation vulnerability in Elasticsearch versions 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 that allows an attacker to escalate their privileges by creating API keys and authentication tokens.
What is the severity of CVE-2020-7014?
CVE-2020-7014 has a severity score of 8.8 (high).
Which software versions are affected by CVE-2020-7014?
Elasticsearch versions 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 are affected by CVE-2020-7014.
How can an attacker exploit CVE-2020-7014?
An attacker can exploit CVE-2020-7014 by generating an API key and an authentication token.
Are there any references for CVE-2020-7014?
Yes, you can find references for CVE-2020-7014 at the following links: [NetApp Advisory](https://security.netapp.com/advisory/ntap-20200619-0003/) and [Elastic Security](https://www.elastic.co/community/security/).