API Key Authorization Bypass in Elastic Enterprise Search App Search Versions Prior to 7.14.0

API Key Authorization Bypass in Elastic Enterprise Search App Search Versions Prior to 7.14.0

CVE-2021-22149 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Elastic Enterprise Search App Search versions before 7.14.0 are vulnerable to an issue where API keys were missing authorization via an alternate route. Using this vulnerability, an authenticated attacker could utilize API keys belonging to higher privileged users.

Learn more about our Api Penetration Testing.