CVE-2020-7009

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
31/03/2020
Last modified:
09/04/2020

Description

Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API key being generated with elevated privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:* 6.7.0 (including) 6.8.8 (excluding)
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:* 7.0.0 (including) 7.6.2 (excluding)