← Back

Elastic

elastic

238 CVEs • 30 products

Products (30)

Click to collapse
Toggle
Kibana
kibana
Elasticsearch
elasticsearch
Logstash
logstash
X Pack
x-pack
Elastic Agent
elastic_agent
Apm Agent
apm_agent
Apm Server
apm_server
Kibana X Pack
kibana_x-pack
Endgame
endgame
Filebeat
filebeat
Fleet Server
fleet_server
Elastic Beats
elastic_beats
Winlogbeat
winlogbeat
Apm Agent Ruby
apm-agent-ruby
Endpoint
endpoint
Apm .net Agent
apm_.net_agent
Apm Java Agent
apm_java_agent

CVEs (238)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Elastic
1Kibana
Nov 21, 2024
Mar 30, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The fix in Kibana for ESA-2017-23 was incomplete. With X-Pack security enabled, Kibana versions before 6.1.3 and 5.6.7 have an open redirect vulnerability on the login page that would enable an attacker to craft a link t...Show more
The fix in Kibana for ESA-2017-23 was incomplete. With X-Pack security enabled, Kibana versions before 6.1.3 and 5.6.7 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.Show less
1Elastic
1Kibana
Nov 21, 2024
Mar 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Kibana versions 5.1.1 to 6.1.2 and 5.6.6 had a cross-site scripting (XSS) vulnerability via the colored fields formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on...Show more
Kibana versions 5.1.1 to 6.1.2 and 5.6.6 had a cross-site scripting (XSS) vulnerability via the colored fields formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.Show less
1Elastic
1Logstash
Nov 21, 2024
Mar 30, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
When logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log sensitive information.
1Elastic
1Elasticsearch
Nov 21, 2024
Mar 6, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnera...Show more
Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerabilityShow less
1Elastic
1Kibana
May 13, 2026
Dec 8, 2017
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The Kibana fix for CVE-2017-8451 was found to be incomplete. With X-Pack installed, Kibana versions before 6.0.1 and 5.6.5 have an open redirect vulnerability on the login page that would enable an attacker to craft a li...Show more
The Kibana fix for CVE-2017-8451 was found to be incomplete. With X-Pack installed, Kibana versions before 6.0.1 and 5.6.5 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.Show less
1Elastic
1Kibana
May 13, 2026
Dec 8, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Kibana versions prior to 6.0.1 and 5.6.5 had a cross-site scripting (XSS) vulnerability via URL fields that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other K...Show more
Kibana versions prior to 6.0.1 and 5.6.5 had a cross-site scripting (XSS) vulnerability via URL fields that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.Show less
1Elastic
1X Pack
May 13, 2026
Sep 29, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An error was found in the permission model used by X-Pack Alerting 5.0.0 to 5.6.0 whereby users mapped to certain built-in roles could create a watch that results in that user gaining elevated privileges.
1Elastic
1X Pack
May 13, 2026
Sep 29, 2017
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index' permissions on an index in a cluster, they may be able to issue both delete and index requests agai...Show more
An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index' permissions on an index in a cluster, they may be able to issue both delete and index requests against that index.Show less
2Elastic
Elasticsearch
2Kibana
Kibana
May 13, 2026
Sep 29, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Kibana versions prior to 5.6.1 had a cross-site scripting (XSS) vulnerability in Timelion that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
1Elastic
1X Pack
May 13, 2026
Aug 18, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An error was found in the X-Pack Security TLS trust manager for versions 5.0.0 to 5.5.1. If reloading the trust material fails the trust manager will be replaced with an instance that trusts all certificates. This could...Show more
An error was found in the X-Pack Security TLS trust manager for versions 5.0.0 to 5.5.1. If reloading the trust material fails the trust manager will be replaced with an instance that trusts all certificates. This could allow any node using any certificate to join a cluster. The proper behavior in this instance is for the TLS trust manager to deny all certificates.Show less
2Elastic
Elasticsearch
2Logstash
Logstash
May 13, 2026
Aug 9, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might allow attackers to obtain sensitive informa...Show more
Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might allow attackers to obtain sensitive information via a man-in-the-middle attack.Show less
1Elastic
1X Pack
May 13, 2026
Jul 7, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Elasticsearch X-Pack Security versions 5.0.0 to 5.4.3, when enabled, can result in the Elasticsearch _nodes API leaking sensitive configuration information, such as the paths and passphrases of SSL keys that were configu...Show more
Elasticsearch X-Pack Security versions 5.0.0 to 5.4.3, when enabled, can result in the Elasticsearch _nodes API leaking sensitive configuration information, such as the paths and passphrases of SSL keys that were configured as part of an authentication realm. This could allow an authenticated Elasticsearch user to improperly view these details.Show less
1Elastic
1Kibana
May 13, 2026
Jun 30, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In Kibana X-Pack security versions prior to 5.4.3 if a Kibana user opens a crafted Kibana URL the result could be a redirect to an improperly initialized Kibana login screen. If the user enters credentials on this screen...Show more
In Kibana X-Pack security versions prior to 5.4.3 if a Kibana user opens a crafted Kibana URL the result could be a redirect to an improperly initialized Kibana login screen. If the user enters credentials on this screen, the credentials will appear in the URL bar. The credentials could then be viewed by untrusted parties or logged into the Kibana access logs.Show less
2Elastic
Elasticsearch
2Logstash
Logstash
May 13, 2026
Jun 27, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Logstash 1.5.x before 1.5.3 and 1.4.x before 1.4.4 allows remote attackers to read communications between Logstash Forwarder agent and Logstash server.
1Elastic
1Kibana
May 13, 2026
Jun 16, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Kibana versions prior to 5.2.1 configured for SSL client access, file descriptors will fail to be cleaned up after certain requests and will accumulate over time until the process crashes.
1Elastic
1Kibana
May 13, 2026
Jun 16, 2017
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
With X-Pack installed, Kibana versions before 5.3.1 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.
1Elastic
1X Pack
May 13, 2026
Jun 16, 2017
N/A· v4
7.5 HIGH· v3
4.0 MEDIUM· v2
X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users without access to a document and/or field may have been able to access this information.
1Elastic
1X Pack
May 13, 2026
Jun 16, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules used a mix of grant and exclude rules when merging multiple rules with field level security rules f...Show more
X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules used a mix of grant and exclude rules when merging multiple rules with field level security rules for the same index.Show less
1Elastic
1Kibana
May 13, 2026
Jun 16, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Kibana versions after and including 4.3 and before 4.6.2 are vulnerable to a cross-site scripting (XSS) attack.
1Elastic
1Kibana
May 13, 2026
Jun 16, 2017
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link in the Kibana domain that redirects to an arbitrary website.