Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-37937
HistoryNov 22, 2023 - 12:00 a.m.

CVE-2021-37937

2023-11-2200:00:00
ubuntu.com
ubuntu.com
10
api key
fleet-server
service account
privilege escalation
unix

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.1 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

19.3%

An issue was found with how API keys are created with the Fleet-Server
service account. When an API key is created with a service account, it is
possible that the API key could be created with higher privileges than
intended. Using this vulnerability, a compromised Fleet-Server service
account could escalate themselves to a super-user.

OSVersionArchitecturePackageVersionFilename
ubuntu16.04noarchelasticsearch< anyUNKNOWN

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.1 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

19.3%

Related for UB:CVE-2021-37937