PT-2021-4651 · Elastic · Enterprise Search App Search

Published

2021-08-03

·

Updated

2022-10-25

·

CVE-2021-22149

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Elastic Enterprise Search App Search versions prior to 7.14.0
Description The issue is related to missing authorization for API keys via an alternate route. An authenticated attacker could exploit this to utilize API keys belonging to higher privileged users, potentially leading to privilege escalation. The vulnerability is associated with incorrect permission assignment for API keys.
Recommendations For Elastic Enterprise Search App Search versions prior to 7.14.0, update to version 7.14.0 or later to resolve the issue. As a temporary workaround, consider restricting access to API keys and limiting the privileges associated with them until a patch is applied. Avoid using API keys that belong to higher privileged users in the affected versions.

Fix

Incorrect Permission

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2021-05344
CVE-2021-22149

Affected Products

Enterprise Search App Search