org.elasticsearch.plugin:x-pack-security@7.13.3 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the org.elasticsearch.plugin:x-pack-security package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Privilege Escalation

org.elasticsearch.plugin:x-pack-security is an Elasticsearch Expanded Pack Plugin - Security

Affected versions of this package are vulnerable to Privilege Escalation. When the Fleet-Server service account is used to create an API key, an attacker can escalate their privileges to a super-user level by exploiting the improper privilege management. This is only exploitable if the attacker has compromised the Fleet-Server service account.

How to fix Privilege Escalation?

Upgrade org.elasticsearch.plugin:x-pack-security to version 7.14.1 or higher.

[7.13.0,7.14.1)