Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-37937


An issue was found with how API keys are created with the Fleet-Server service account. When an API key is created with a service account, it is possible that the API key could be created with higher privileges than intended. Using this vulnerability, a compromised Fleet-Server service account could escalate themselves to a super-user.


Published

2023-11-22T02:15:42.043

Last Modified

2024-11-21T06:16:06.437

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-269
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application elastic elasticsearch ≤ 7.14.0 Yes

References