Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

Elastic Elasticsearch Privilege Escalation Vulnerability (ESA-2021-25)

Information

Severity

Severity

Medium

Family

Family

Privilege escalation

CVSSv2 Base

CVSSv2 Base

6.2

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:H/Au:M/C:C/I:C/A:N

Solution Type

Solution Type

Vendor Patch

Created

Created

2 years ago

Modified

Modified

2 years ago

Summary

Elastic Elasticsearch is prone to a privilege escalation vulnerability.

Insight

Insight

An issue was found with how API keys are created with the fleet-server service account. When an API key is created with a service account, it is possible that the API key could be created with higher privileges than intended. Using this vulnerability, a compromised fleet-server service account could escalate themselves to a super-user.

Affected Software

Affected Software

Elastic Elasticsearch version 7.13.0 through 7.14.0.

Detection Method

Detection Method

Checks if a vulnerable version is present on the target host.

Solution

Solution

Update to version 7.14.1 or later.

Common Vulnerabilities and Exposures (CVE)