Vulnerabilities > CVE-2021-37937 - Unspecified vulnerability in Elastic Elasticsearch
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
An issue was found with how API keys are created with the Fleet-Server service account. When an API key is created with a service account, it is possible that the API key could be created with higher privileges than intended. Using this vulnerability, a compromised Fleet-Server service account could escalate themselves to a super-user.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 6 |