8.8
CVSSv3

CVE-2021-22149

Published: 15/09/2021 Updated: 25/10/2022
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Elastic Enterprise Search App Search versions prior to 7.14.0 are vulnerable to an issue where API keys were missing authorization via an alternate route. Using this vulnerability, an authenticated attacker could utilize API keys belonging to higher privileged users.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

elastic enterprise search

Vendor Advisories

A flaw in Elastic App Search in Elastic Enterprise Search versions prior to 7140 was discovered where API keys were missing authorization via an alternate route Using this vulnerability, an authenticated attacker could utilize API keys belonging to higher privileged users ...