First published: Wed Jun 03 2020(Updated: )
The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication tokens. An attacker who is able to generate an API key and an authentication token can perform a series of steps that result in an authentication token being generated with elevated privileges.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic Elasticsearch | >=6.7.0<=6.8.7 | |
Elastic Elasticsearch | >=7.0.0<=7.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7014 is a privilege escalation vulnerability in Elasticsearch versions 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 that allows an attacker to escalate their privileges by creating API keys and authentication tokens.
CVE-2020-7014 has a severity score of 8.8 (high).
Elasticsearch versions 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 are affected by CVE-2020-7014.
An attacker can exploit CVE-2020-7014 by generating an API key and an authentication token.
Yes, you can find references for CVE-2020-7014 at the following links: [NetApp Advisory](https://security.netapp.com/advisory/ntap-20200619-0003/) and [Elastic Security](https://www.elastic.co/community/security/).