CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Elastic 1Elastic Cloud On Kubernetes Sep 4, 2026 Sep 2, 2026 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification of data via Metadata Spoofing (CAPEC-690). An actor holding limited Kubernetes permissions confined to a single...Show more |
Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association has been denied by...Show more |
1Elastic 1Elastic Cloud On Kubernetes Sep 4, 2026 Aug 13, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Cleartext Storage of Sensitive Information in an Environment Variable (CWE-526) in Elastic Cloud on Kubernetes (ECK) can lead to information disclosure via Retrieve Embedded Sensitive Data (CAPEC-37). When ECK reconciles...Show more |
1Elastic 1Elastic Cloud On Kubernetes Sep 3, 2026 Aug 13, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret references from an annotation on secrets it manages, and it accepts the namespace recorded in each reference without validating that the reference is...Show more |
1Elastic 1Elastic Cloud On Kubernetes Jun 17, 2026 Oct 26, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requests to an APM Server being accepted and the data ingested into this APM deployment. |
1Elastic 1Elastic Cloud On Kubernetes Jun 17, 2026 Jun 3, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator. If an attacker is able to determine when the current Elastic Stack cluster was deployed they may be able...Show more |