VDB
CVE-2020-7010
CVE-2020-7010
REJECTED
CVSS 7.5 HIGH
Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator. If an attacker is able to determine when the current Elastic Stack cluster was deployed they may be able to more easily brute force the Elasticsearch credentials generated by ECK.
EPSS 1.44% · 71.3th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
1.44%
71.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:22.04:LTS | kubernetes | 1.0, 0 |
| Ubuntu:24.04:LTS | kubernetes | 0, 1.0 |
| Ubuntu:Pro:20.04:LTS | kubernetes | 0, 1.0 |
Timeline
- Jun 3, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Dec 28, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 1, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Sep 6, 2022 EPSS Score
- Nov 8, 2022 EPSS Score
References
- https://ubuntu.com/security/CVE-2020-7010 third-party-advisory
- https://www.elastic.co/community/security/ third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2020-7010 third-party-advisory