Логотип exploitDog
bind:CVE-2020-7014
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-7014

Количество 6

Количество 6

ubuntu логотип

CVE-2020-7014

больше 5 лет назад

The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication tokens. An attacker who is able to generate an API key and an authentication token can perform a series of steps that result in an authentication token being generated with elevated privileges.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2020-7014

больше 5 лет назад

The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication tokens. An attacker who is able to generate an API key and an authentication token can perform a series of steps that result in an authentication token being generated with elevated privileges.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2020-7014

больше 5 лет назад

The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication tokens. An attacker who is able to generate an API key and an authentication token can perform a series of steps that result in an authentication token being generated with elevated privileges.

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2020-7014

около 4 лет назад

The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication tokens. An attacker who is able to generate an API key and an authentication token can perform a series of steps that result in an authentication token being generated with elevated privileges.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2020-7014

больше 5 лет назад

The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch ve ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-hqqv-9x3v-mp7w

почти 5 лет назад

Privilege Escalation Flaw in Elasticsearch

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-7014

The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication tokens. An attacker who is able to generate an API key and an authentication token can perform a series of steps that result in an authentication token being generated with elevated privileges.

CVSS3: 8.8
0%
Низкий
больше 5 лет назад
redhat логотип
CVE-2020-7014

The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication tokens. An attacker who is able to generate an API key and an authentication token can perform a series of steps that result in an authentication token being generated with elevated privileges.

CVSS3: 8.8
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-7014

The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication tokens. An attacker who is able to generate an API key and an authentication token can perform a series of steps that result in an authentication token being generated with elevated privileges.

CVSS3: 8.8
0%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-7014

The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication tokens. An attacker who is able to generate an API key and an authentication token can perform a series of steps that result in an authentication token being generated with elevated privileges.

CVSS3: 8.8
0%
Низкий
около 4 лет назад
debian логотип
CVE-2020-7014

The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch ve ...

CVSS3: 8.8
0%
Низкий
больше 5 лет назад
github логотип
GHSA-hqqv-9x3v-mp7w

Privilege Escalation Flaw in Elasticsearch

CVSS3: 8.8
0%
Низкий
почти 5 лет назад

Уязвимостей на страницу