CVE-2021-22148: High severity elastic enterprise search vulnerability
Elastic Enterprise Search App Search versions before 7.14.0 was vulnerable to an issue where API keys were not bound to the same engines as their creator. This could lead to a less privileged user gaining access to unauthorized engines.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-22148?
CVE-2021-22148 is a vulnerability in Elastic Enterprise Search App Search versions before 7.14.0.
How does CVE-2021-22148 affect Elastic Enterprise Search?
CVE-2021-22148 allows a less privileged user to gain access to unauthorized engines in Elastic Enterprise Search.
What is the severity of CVE-2021-22148?
CVE-2021-22148 has a severity rating of 8.8 (high).
How can I fix CVE-2021-22148?
To fix CVE-2021-22148, upgrade to Elastic Enterprise Search App Search version 7.14.0 or later.
Where can I find more information about CVE-2021-22148?
You can find more information about CVE-2021-22148 at the following references: [Elastic Discuss](https://discuss.elastic.co/t/elastic-stack-7-14-0-security-update/280344) and [Elastic Security](https://www.elastic.co/community/security/).