Missing Authorization Affecting org.elasticsearch:elasticsearch package, versions [,7.17.1) [8.0.0,8.0.1)


0.0
low

Snyk CVSS

    Attack Complexity High

    Threat Intelligence

    EPSS 0.05% (22nd percentile)
Expand this section
NVD
4.3 medium
Expand this section
Red Hat
4.3 medium

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-JAVA-ORGELASTICSEARCH-2431238
  • published 22 Mar 2022
  • disclosed 28 Feb 2022
  • credit Unknown

How to fix?

Upgrade org.elasticsearch:elasticsearch to version 7.17.1, 8.0.1 or higher.

Overview

org.elasticsearch:elasticsearch is a Distributed, RESTful Search Engine.

Affected versions of this package are vulnerable to Missing Authorization by allowing users with Read access to the Uptime feature to modify alerting rules. That being said, any new or modified rules would not be enabled, and a user with this privilege could not modify alerting connectors.