Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API key being generated with elevated privileges.
{ "nvd_published_at": "2020-03-31T19:15:00Z", "cwe_ids": [ "CWE-266", "CWE-269" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-06-23T18:02:18Z" }