Loading HuntDB...

GHSA-hqqv-9x3v-mp7w

GitHub Security Advisory

Privilege Escalation Flaw in Elasticsearch

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication tokens. An attacker who is able to generate an API key and an authentication token can perform a series of steps that result in an authentication token being generated with elevated privileges.

Affected Packages

Maven org.elasticsearch:elasticsearch
Affected versions: 6.7.0 (fixed in 6.8.8)
Maven org.elasticsearch:elasticsearch
Affected versions: 7.0.0 (fixed in 7.6.2)

Related CVEs

Key Information

GHSA ID
GHSA-hqqv-9x3v-mp7w
Published
March 18, 2021 7:27 PM
Last Modified
March 16, 2021 4:31 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.elasticsearch:elasticsearch
GitHub Reviewed
✓ Yes

Dataset

Last updated: November 26, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.