CVE-2024-37282: Critical severity Elastic Elastic Cloud Enterprise vulnerability
It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subsequently used to create new API keys that have elevated privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37282?
CVE-2024-37282 is rated as a high severity vulnerability due to the potential for elevated privileges through API key misuse.
How do I fix CVE-2024-37282?
To fix CVE-2024-37282, ensure you update your Elastic Cloud Enterprise installation to version 3.7.2 or later.
What versions of Elastic Cloud Enterprise are affected by CVE-2024-37282?
CVE-2024-37282 affects Elastic Cloud Enterprise versions between 3.0.0 and 3.7.2 inclusive.
What are the implications of CVE-2024-37282?
The implications of CVE-2024-37282 include unauthorized creation of elevated privilege API keys, which can lead to significant security risks.
Who is impacted by CVE-2024-37282?
Any user or organization utilizing vulnerable versions of Elastic Cloud Enterprise is impacted by CVE-2024-37282.