Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gfv5-grx2-9jw2

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Improper Privilege Management in Elasticsearch

Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API key being generated with elevated privileges.

Пакеты

Наименование

org.elasticsearch:elasticsearch

maven
Затронутые версииВерсия исправления

>= 6.7.0, <= 6.8.7

6.8.8

Наименование

org.elasticsearch:elasticsearch

maven
Затронутые версииВерсия исправления

>= 7.0.0, <= 7.6.1

7.6.2

EPSS

Процентиль: 82%
0.01753
Низкий

8.8 High

CVSS3

Дефекты

CWE-266
CWE-269

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 6 лет назад

Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API key being generated with elevated privileges.

CVSS3: 8.8
redhat
почти 6 лет назад

Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API key being generated with elevated privileges.

CVSS3: 8.8
nvd
почти 6 лет назад

Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API key being generated with elevated privileges.

CVSS3: 8.8
msrc
около 4 лет назад

Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API key being generated with elevated privileges.

CVSS3: 8.8
debian
почти 6 лет назад

Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 ...

EPSS

Процентиль: 82%
0.01753
Низкий

8.8 High

CVSS3

Дефекты

CWE-266
CWE-269