CVE-2021-22149
Summary
| CVE | CVE-2021-22149 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-15 12:15:00 UTC |
| Updated | 2022-10-25 18:30:00 UTC |
| Description | Elastic Enterprise Search App Search versions before 7.14.0 are vulnerable to an issue where API keys were missing authorization via an alternate route. Using this vulnerability, an authenticated attacker could utilize API keys belonging to higher privileged users. |
Risk And Classification
Problem Types: CWE-862
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Elastic | Enterprise Search | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Elastic Stack 7.14.0 Security Update - Security Announcements - Discuss the Elastic Stack | MISC | discuss.elastic.co | |
| Security issues | Elastic | MISC | www.elastic.co | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.