An issue was found with how API keys are created with the Fleet-Server service account. When an API key is created with a service account, it is possible that the API key could be created with higher privileges than intended. Using this vulnerability, a compromised Fleet-Server service account could escalate themselves to a super-user.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Elasticsearch | Elastic | 7.13.0 (including) | 7.14.0 (including) |
Elasticsearch | Ubuntu | bionic | * |
Elasticsearch | Ubuntu | trusty | * |
Elasticsearch | Ubuntu | xenial | * |