QID 730233

Date Published: 2021-10-14

QID 730233: Elasticsearch Access Control Vulnerability (ESA-2021-25)

Elasticsearch is a search server based on Lucene that provides a distributed, multitenant-capable full-text search engine with an HTTP web interface and schema-free JSON documents.

Affected with following vulnerability:
CVE-2021-37937: An issue was found with how API keys are created with the fleet-server service account. When an API key is created with a service account, it is possible that the API key could be created with higher privileges than intended. Using this vulnerability, a compromised fleet-server service account could escalate themselves to a super-user.

Affected Versions:
Elasticsearch versions prior to 7.14.1

QID detection logic:
Checks the vulnerable versions of ElasticSearch.

Successful exploitation of this vulnerability may allow an attacker to escalate themselves to a super-user from a compromised fleet-server service account.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Customers are advised to upgrade to Elasticsearch version 7.14.1 to remediate this vulnerability.
    Vendor References

    CVEs related to QID 730233

    Software Advisories
    Advisory ID Software Component Link
    ESA-2021-25 URL Logo www.elastic.co/community/security/