← Back

Elastic

elastic

238 CVEs • 30 products

Products (30)

Click to collapse
Toggle
Kibana
kibana
Elasticsearch
elasticsearch
Logstash
logstash
X Pack
x-pack
Elastic Agent
elastic_agent
Apm Agent
apm_agent
Apm Server
apm_server
Kibana X Pack
kibana_x-pack
Endgame
endgame
Filebeat
filebeat
Fleet Server
fleet_server
Elastic Beats
elastic_beats
Winlogbeat
winlogbeat
Apm Agent Ruby
apm-agent-ruby
Endpoint
endpoint
Apm .net Agent
apm_.net_agent
Apm Java Agent
apm_java_agent

CVEs (238)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Elastic
1Elasticsearch
Jun 17, 2026
Oct 22, 2020
N/A· v4
3.1 LOW· v3
3.5 LOW· v2
Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain complex...Show more
Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain complex queries. This could result in the search disclosing the existence of documents the attacker should not be able to view. This could result in an attacker gaining additional insight into potentially sensitive indices.Show less
1Elastic
1Elasticsearch
Jun 17, 2026
Aug 18, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security. If a user runs the same query another more privileged user recently ran, the scrolling...Show more
In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security. If a user runs the same query another more privileged user recently ran, the scrolling search can leak fields that should be hidden. This could result in an attacker gaining additional permissions against a restricted index.Show less
1Elastic
1Enterprise Search
Jun 17, 2026
Aug 18, 2020
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, they will be able to view the administrator API credentials. These crede...Show more
Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, they will be able to view the administrator API credentials. These credentials could allow the developer user to conduct operations with the same permissions of the App Search administrator.Show less
1Elastic
1Kibana
Jun 17, 2026
Jun 3, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Kibana versions before 6.8.9 and 7.7.0 contains a stored XSS flaw in the TSVB visualization. An attacker who is able to edit or create a TSVB visualization could allow the attacker to obtain sensitive information from, o...Show more
Kibana versions before 6.8.9 and 7.7.0 contains a stored XSS flaw in the TSVB visualization. An attacker who is able to edit or create a TSVB visualization could allow the attacker to obtain sensitive information from, or perform destructive actions, on behalf of Kibana users who edit the TSVB visualization.Show less
1Elastic
1Elasticsearch
Jun 17, 2026
Jun 3, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication to...Show more
The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication tokens. An attacker who is able to generate an API key and an authentication token can perform a series of steps that result in an authentication token being generated with elevated privileges.Show less
2Elastic
Redhat
2Kibana
Openshift Container Platform
Jun 17, 2026
Jun 3, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary co...Show more
Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana process on the host system.Show less
1Elastic
1Kibana
Jun 17, 2026
Jun 3, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authenticated attacker with privileges to write to the Kibana index could insert data that would cause Kib...Show more
Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authenticated attacker with privileges to write to the Kibana index could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana process on the host system.Show less
1Elastic
1Elastic App Search
Jun 17, 2026
Jun 3, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Elastic App Search versions before 7.7.0 contain a cross site scripting (XSS) flaw when displaying document URLs in the Reference UI. If the Reference UI injects a URL into a result, that URL will be rendered by the web...Show more
Elastic App Search versions before 7.7.0 contain a cross site scripting (XSS) flaw when displaying document URLs in the Reference UI. If the Reference UI injects a URL into a result, that URL will be rendered by the web browser. If an attacker is able to control the contents of such a field, they could execute arbitrary JavaScript in the victim�s web browser.Show less
1Elastic
1Elastic Cloud On Kubernetes
Jun 17, 2026
Jun 3, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator. If an attacker is able to determine when the current Elastic Stack cluster was deployed they may be able...Show more
Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator. If an attacker is able to determine when the current Elastic Stack cluster was deployed they may be able to more easily brute force the Elasticsearch credentials generated by ECK.Show less
1Elastic
1Elasticsearch
Jun 17, 2026
Mar 31, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of...Show more
Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API key being generated with elevated privileges.Show less
1Elastic
1Kibana
Jun 17, 2026
Dec 18, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with the ability to create coordinate map visualizations could create a malici...Show more
Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with the ability to create coordinate map visualizations could create a malicious visualization. If another Kibana user views that visualization or a dashboard containing the visualization it could execute JavaScript in the victim�s browser.Show less
1Elastic
1Logstash
Jun 17, 2026
Oct 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Logstash versions before 7.4.1 and 6.8.4 contain a denial of service flaw in the Logstash Beats input plugin. An unauthenticated user who is able to connect to the port the Logstash beats input could send a specially cra...Show more
Logstash versions before 7.4.1 and 6.8.4 contain a denial of service flaw in the Logstash Beats input plugin. An unauthenticated user who is able to connect to the port the Logstash beats input could send a specially crafted network packet that would cause Logstash to stop responding.Show less
1Elastic
1Elasticsearch
Jun 17, 2026
Oct 30, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker could send a specially crafted request and determine if a username exist...Show more
Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker could send a specially crafted request and determine if a username exists in the Elasticsearch native realm.Show less
1Elastic
1Kibana
Jun 17, 2026
Oct 1, 2019
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is possible to read arbitrary files from the local filesystem of the Kibana...Show more
A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is possible to read arbitrary files from the local filesystem of the Kibana instance running Code with the permission of the Kibana system user.Show less
1Elastic
1Apm Agent
Jun 17, 2026
Aug 22, 2019
N/A· v4
7.2 HIGH· v3
6.4 MEDIUM· v2
When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw if a remote attacker can control the proxy header. This could result in an attacker redirecting coll...Show more
When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw if a remote attacker can control the proxy header. This could result in an attacker redirecting collected APM data to a proxy of their choosing.Show less
1Elastic
1Kibana
Jun 17, 2026
Jul 30, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Kibana versions before 6.8.2 and 7.2.1 contain a server side request forgery (SSRF) flaw in the graphite integration for Timelion visualizer. An attacker with administrative Kibana access could set the timelion:graphite....Show more
Kibana versions before 6.8.2 and 7.2.1 contain a server side request forgery (SSRF) flaw in the graphite integration for Timelion visualizer. An attacker with administrative Kibana access could set the timelion:graphite.url configuration option to an arbitrary URL. This could possibly lead to an attacker accessing external URL resources as the Kibana process on the host system.Show less
1Elastic
1Apm Agent Ruby
Jun 17, 2026
Jul 30, 2019
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
A TLS certificate validation flaw was found in Elastic APM agent for Ruby versions before 2.9.0. When specifying a trusted server CA certificate via the 'server_ca_cert' setting, the Ruby agent would not properly verify...Show more
A TLS certificate validation flaw was found in Elastic APM agent for Ruby versions before 2.9.0. When specifying a trusted server CA certificate via the 'server_ca_cert' setting, the Ruby agent would not properly verify the certificate returned by the APM server. This could result in a man in the middle style attack against the Ruby agent.Show less
1Elastic
1Elasticsearch
Jun 17, 2026
Jul 30, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gai...Show more
A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gain access to response header containing sensitive data from another user.Show less
1Elastic
1Winlogbeat
Jun 17, 2026
Mar 25, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Winlogbeat versions before 5.6.16 and 6.6.2 had an insufficient logging flaw. An attacker able to inject certain characters into a log entry could prevent Winlogbeat from recording the event.
2Elastic
Netapp
2Active Iq Performance Analytics Services
Logstash
Jun 17, 2026
Mar 25, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified as part of the Logstash configuration, the credentials for the URL coul...Show more
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified as part of the Logstash configuration, the credentials for the URL could be inadvertently logged as part of the error message.Show less