BIT-elasticsearch-2020-7014

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/elasticsearch/BIT-elasticsearch-2020-7014.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-elasticsearch-2020-7014
Aliases
Published
2024-03-06T10:54:49.268Z
Modified
2024-03-06T11:25:28.861Z
Summary
[none]
Details

The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication tokens. An attacker who is able to generate an API key and an authentication token can perform a series of steps that result in an authentication token being generated with elevated privileges.

Database specific
{
    "cpes": [
        "cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / elasticsearch

Package

Name
elasticsearch
Purl
pkg:bitnami/elasticsearch

Severity

  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
6.7.0
Fixed
6.8.7
Introduced
7.0.0
Fixed
7.6.1