First published: Wed Sep 15 2021(Updated: )
Elastic Enterprise Search App Search versions before 7.14.0 was vulnerable to an issue where API keys were not bound to the same engines as their creator. This could lead to a less privileged user gaining access to unauthorized engines.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic Enterprise Search | <7.14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22148 is a vulnerability in Elastic Enterprise Search App Search versions before 7.14.0.
CVE-2021-22148 allows a less privileged user to gain access to unauthorized engines in Elastic Enterprise Search.
CVE-2021-22148 has a severity rating of 8.8 (high).
To fix CVE-2021-22148, upgrade to Elastic Enterprise Search App Search version 7.14.0 or later.
You can find more information about CVE-2021-22148 at the following references: [Elastic Discuss](https://discuss.elastic.co/t/elastic-stack-7-14-0-security-update/280344) and [Elastic Security](https://www.elastic.co/community/security/).