← Back

Elastic

elastic

238 CVEs • 30 products

Products (30)

Click to collapse
Toggle
Kibana
kibana
Elasticsearch
elasticsearch
Logstash
logstash
X Pack
x-pack
Elastic Agent
elastic_agent
Apm Agent
apm_agent
Apm Server
apm_server
Kibana X Pack
kibana_x-pack
Endgame
endgame
Filebeat
filebeat
Fleet Server
fleet_server
Elastic Beats
elastic_beats
Winlogbeat
winlogbeat
Apm Agent Ruby
apm-agent-ruby
Endpoint
endpoint
Apm .net Agent
apm_.net_agent
Apm Java Agent
apm_java_agent

CVEs (238)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Elastic
1Kibana
May 13, 2026
Jun 16, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any authenticated user could make requests to those services regardless of...Show more
With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any authenticated user could make requests to those services regardless of their own permissions.Show less
1Elastic
1Logstash
May 13, 2026
Jun 16, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, Netflow v9 or IPFIX packets could perform a denial of service attack on the Logstash instance. The e...Show more
Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, Netflow v9 or IPFIX packets could perform a denial of service attack on the Logstash instance. The errors resulting from these crafted inputs are not handled by the codec and can cause the Logstash process to exit.Show less
1Elastic
1Logstash
May 13, 2026
Jun 16, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Logstash prior to version 2.1.2, the CSV output can be attacked via engineered input that will create malicious formulas in the CSV data.
1Elastic
1Logstash
May 13, 2026
Jun 16, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could contain sensitive information.
1Elastic
1Kibana
May 13, 2026
Jun 16, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScript in users' browsers.
1Elastic
1Kibana
May 13, 2026
Jun 16, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers could be written to the log files. This information could be used to hijack sessions of other users when...Show more
Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers could be written to the log files. This information could be used to hijack sessions of other users when using Kibana behind some form of authentication such as Shield.Show less
1Elastic
1Kibana Reporting
May 13, 2026
Jun 16, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Kibana Reporting plugin version 2.4.0 is vulnerable to a CSRF vulnerability that could allow an attacker to generate superfluous reports whenever an authenticated Kibana user navigates to a specially-crafted page.
1Elastic
1Kibana
May 13, 2026
Jun 16, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Kibana versions prior to 4.1.3 and 4.2.1 are vulnerable to a XSS attack.
1Elastic
1X Pack
May 13, 2026
Jun 5, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to index aliases. This bug could allow a user with restricted permissions to view data they should not have...Show more
Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to index aliases. This bug could allow a user with restricted permissions to view data they should not have access to when performing certain operations against an index alias.Show less
1Elastic
1Kibana
May 13, 2026
Jun 5, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Ki...Show more
Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.Show less
1Elastic
1Kibana
May 13, 2026
Jun 5, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Kibana version 5.4.0 was affected by a Cross Site Scripting (XSS) bug in the Time Series Visual Builder. This bug could allow an attacker to obtain sensitive information from Kibana users.
1Elastic
1X Pack
May 13, 2026
Jun 5, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality. This bug prevents transitioning into the specified user specified in a run_as request. If a role has been cr...Show more
Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality. This bug prevents transitioning into the specified user specified in a run_as request. If a role has been created using a template that contains the _user properties, the behavior of run_as will be incorrect. Additionally if the run_as user specified does not exist, the transition will not happen.Show less
1Elastic
1Kibana
May 6, 2026
Dec 7, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Elasticsearch Kibana before 4.1.3 and 4.2.x before 4.2.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
1Elastic
1Logstash
May 6, 2026
Jun 15, 2015
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Directory traversal vulnerability in the file output plugin in Elasticsearch Logstash before 1.4.3 allows remote attackers to write to arbitrary files via vectors related to dynamic field references in the path option.
1Elastic
1Kibana
May 6, 2026
Jun 15, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Elasticsearch Kibana 4.x before 4.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
2Elastic
Redhat
2Elasticsearch
Fuse
Apr 22, 2026
Feb 17, 2015
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
2Elastic
Elasticsearch
2Elasticsearch
Elasticsearch
Apr 22, 2026
Jul 28, 2014
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only vio...Show more
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.Show less
1Elastic
1Logstash
May 6, 2026
Jul 22, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows remote attackers to execute arbitrary commands via a crafted event in (1) zabbix.rb or (2) nagios_nsca.rb in outputs/.