CVE-2020-7009
HIGH8.8EPSS 0.43%Improper Privilege Management in Elasticsearch
發布日:2022/5/24修改日:2025/4/3
描述
Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API key being generated with elevated privileges.
受影響套件(2)
- Bitnami/elasticsearch>= 6.7.0, < 6.8.8, >= 7.0.0, < 7.6.2
- Maven/org.elasticsearch:elasticsearch>= 6.7.0, < 6.8.8
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
參考連結(7)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2020-7009
- PATCHhttps://github.com/elastic/elasticsearch
- WEBhttps://discuss.elastic.co/t/elastic-stack-6-8-8-and-7-6-2-security-update/225920
- WEBhttps://security.netapp.com/advisory/ntap-20200403-0004
- WEBhttps://security.netapp.com/advisory/ntap-20200403-0004/
- WEBhttps://www.elastic.co/community/security
- WEBhttps://www.elastic.co/community/security/