CVE-2021-22149

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/09/2021
Last modified:
25/10/2022

Description

Elastic Enterprise Search App Search versions before 7.14.0 are vulnerable to an issue where API keys were missing authorization via an alternate route. Using this vulnerability, an authenticated attacker could utilize API keys belonging to higher privileged users.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:elastic:enterprise_search:*:*:*:*:*:*:*:* 7.14.0 (excluding)