CVE Database
/

CVE-2021-22148

Back to search

CVE-2021-22148

Published: Sep 15, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

Elastic Enterprise Search App Search versions before 7.14.0 was vulnerable to an issue where API keys were not bound to the same engines as their creator. This could lead to a less privileged user gaining access to unauthorized engines.

VendorProductVersions

Elastic

Elastic Enterprise Search

affected
before 7.14.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now