← Back to CVE List

CVE-2021-37937

Published: 2023-11-22T02:15Z
Last Modified: 2024-11-21T06:16Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An issue was found with how API keys are created with the Fleet-Server service account. When an API key is created with a service account, it is possible that the API key could be created with higher privileges than intended. Using this vulnerability, a compromised Fleet-Server service account could escalate themselves to a super-user. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt