CVE-2021-22148
CVE-2021-22148
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS —EPSS 0.9%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
15 sep 2021Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Elastic Enterprise Search App Search versions before 7.14.0 was vulnerable to an issue where API keys were not bound to the same engines as their creator. This could lead to a less privileged user gaining access to unauthorized engines.
Productos afectados
Elastic · Elastic Enterprise Search¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →