Elastic Enterprise Search App Search versions before 7.14.0 are vulnerable to an issue where API keys were missing authorization via an alternate route. Using this vulnerability, an authenticated attacker could utilize API keys belonging to higher privileged users.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2021-9296 | Elastic Enterprise Search App Search versions before 7.14.0 are vulnerable to an issue where API keys were missing authorization via an alternate route. Using this vulnerability, an authenticated attacker could utilize API keys belonging to higher privileged users. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2024-08-03T18:37:17.257Z
Reserved: 2021-01-04T00:00:00
Link: CVE-2021-22149

No data.

Status : Modified
Published: 2021-09-15T12:15:09.073
Modified: 2024-11-21T05:49:36.180
Link: CVE-2021-22149

No data.

No data.