6.5
CVSSv2

CVE-2021-22148

Published: 15/09/2021 Updated: 18/10/2021
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Elastic Enterprise Search App Search versions prior to 7.14.0 was vulnerable to an issue where API keys were not bound to the same engines as their creator. This could lead to a less privileged user gaining access to unauthorized engines.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

elastic enterprise search

Vendor Advisories

A flaw in Elastic App Search in Elastic Enterprise Search versions prior to 7140 was discovered where API keys were not bound to the same engines as their creator This could lead to a less privileged user gaining access to unauthorized engines ...