CVE-2020-7009 PUBLISHED

Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API key being generated with elevated privileges.

EPSS 1.75% · 82.5th percentile

Risk Scores

EPSS Score
1.75%
82.5th percentile

Affected Products

VendorProductVersions
Bitnamielasticsearch6.7.0, 7.0.0
Bitnamielasticsearch7.0.0, 7.0.0, 6.7.0

Timeline

References

Open in Interactive Console →