Security Advisory

CVE-2024-37282

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-06-28 04:58:18
Last updated 2024-08-02 03:50:55
Assigner elastic
State PUBLISHED

Description

It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subsequently used to create new API keys that have elevated privileges.