CVE-2020-7009
31.03.2020, 19:15
Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API key being generated with elevated privileges.Enginsight
Vendor | Product | Version |
---|---|---|
elastic | elasticsearch | 6.7.0 ≤ 𝑥 < 6.8.8 |
elastic | elasticsearch | 7.0.0 ≤ 𝑥 < 7.6.2 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
- CWE-266 - Incorrect Privilege AssignmentA product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
- CWE-269 - Improper Privilege ManagementThe software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
References