ElasticsearchGHSA-hqqv-9x3v-mp7w
Privilege Escalation Flaw in Elasticsearch
Medium8.8CVE-2020-7014 · Published Mar 18, 2021 · updated Feb 17, 2024
The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication tokens. An attacker who is able to generate an API key and an authentication token can perform a series of steps that result in an authentication token being generated with elevated privileges.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.elasticsearch:elasticsearch Maven | >= 6.7.0, < 6.8.8 | 6.8.8 |
| >= 7.0.0, < 7.6.2 | 7.6.2 |
Details and references
More Elasticsearch advisories
All Elasticsearch| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 202021 | Exposure of sensitive information in Elasticsearch | Medium6.5 | 7.14.0 |
| Aug 92021 | Denial of Service in Elasticsearch | Medium5.7 | 6.8.17+1 more |
| Jul 22021 | API information disclosure flaw in Elasticsearch | Medium5.3 | 6.8.15+1 more |
| Mar 182021 | Insufficiently Protected Credentials in Elasticsearch | Medium4.8 | 7.10.2 |
| Mar 182021 | Privilege Context Switching Error in Elasticsearch | Low3.1 | 6.8.13+1 more |
| Mar 182021 | Exposure of Sensitive Information to an Unauthorized Actor | Medium4.3 | 7.11.0 |