Vulnerability Details CVE-2021-37937
An issue was found with how API keys are created with the Fleet-Server service account. When an API key is created with a service account, it is possible that the API key could be created with higher privileges than intended. Using this vulnerability, a compromised Fleet-Server service account could escalate themselves to a super-user.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 41.6%
CVSS Severity
CVSS v3 Score 5.9
Products affected by CVE-2021-37937
-
cpe:2.3:a:elastic:elasticsearch:7.13.0
-
cpe:2.3:a:elastic:elasticsearch:7.13.1
-
cpe:2.3:a:elastic:elasticsearch:7.13.2
-
cpe:2.3:a:elastic:elasticsearch:7.13.3
-
cpe:2.3:a:elastic:elasticsearch:7.13.4
-
cpe:2.3:a:elastic:elasticsearch:7.14.0