Privilege escalation vulnerability in Elasticsearch - CVE-2020-7009 (rpm)ID: oval:org.secpod.oval:def:62436 | Date: (C)2020-04-13 (M)2022-10-10 |
Class: VULNERABILITY | Family: unix |
The host is installed with Elasticsearch 6.7.x through 6.8.7 and 7.x through 7.6.1 and is prone to a privilege escalation vulnerability. A flaw is present in the application, which fails to handle an issue in API Key service. Successful exploitation could allow attackers to perform a series of steps that result in an API key being generated with elevated privileges.