CVE-2020-7014

CVSS v3.1 8.8 (High)
88% Progress
CVSS v2.0 6.5 (Medium)
65% Progress
EPSS 0.10 % (43th)
0.10% Progress
Affected Products 1
Advisories 1

The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication tokens. An attacker who is able to generate an API key and an authentication token can perform a series of steps that result in an authentication token being generated with elevated privileges.

Weaknesses
CWE-266
Incorrect Privilege Assignment
CWE-269
Improper Privilege Management
Related CVEs
CVE Status
PUBLISHED
CNA
Elastic
Published Date
2020-06-03 18:15:23
(4 years ago)
Updated Date
2020-06-19 11:15:10
(4 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Elasticsearch from 6.7.0 version and 6.8.7 and prior versions cpe:2.3:a:elastic:elasticsearch >= 6.7.0 <= 6.8.7
  Elasticsearch from 7.0.0 version and 7.6.1 and prior versions cpe:2.3:a:elastic:elasticsearch >= 7.0.0 <= 7.6.1
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...