CVE-2024-37282

It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subsequently used to create new API keys that have elevated privileges.
Configurations

No configuration.

History

21 Nov 2024, 09:23

Type Values Removed Values Added
Summary
  • (es) Se identificó que, bajo ciertas condiciones previas específicas, una clave API que se creó originalmente con privilegios específicos podría usarse posteriormente para crear nuevas claves API que tengan privilegios elevados.
References () https://discuss.elastic.co/t/elastic-cloud-enterprise-3-7-2-security-update-esa-2024-18/362181 - () https://discuss.elastic.co/t/elastic-cloud-enterprise-3-7-2-security-update-esa-2024-18/362181 -

28 Jun 2024, 10:27

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-28 05:15

Updated : 2024-11-21 09:23


NVD link : CVE-2024-37282

Mitre link : CVE-2024-37282

CVE.ORG link : CVE-2024-37282


JSON object : View

Products Affected

No product.

CWE
CWE-285

Improper Authorization