Elastic
elastic
341 CVEs • 32 products
Products (32)
Click to collapseToggle
Products (32)
Click to collapse
CVEs (341)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gai...Show more |
Winlogbeat versions before 5.6.16 and 6.6.2 had an insufficient logging flaw. An attacker able to inject certain characters into a log entry could prevent Winlogbeat from recording the event. |
2Elastic Netapp2Active Iq Performance Analytics Services LogstashJun 17, 2026 Mar 25, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified as part of the Logstash configuration, the credentials for the URL coul...Show more |
A permission issue was found in Elasticsearch versions before 5.6.15 and 6.6.1 when Field Level Security and Document Level Security are disabled and the _aliases, _shrink, or _split endpoints are used . If the elasticse...Show more |
Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.security.audit.enabled set to true, an attacker could send a request that wil...Show more |
2Elastic Redhat2Kibana Openshift Container PlatformJun 17, 2026 Mar 25, 2019 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascrip...Show more |
Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XSS) vulnerability that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users. |
Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a policy allowing external network access has been added to Elasticsearch's Java Security Manager then...Show more |
2Elastic Redhat2Kibana Openshift Container PlatformNov 21, 2024 Dec 20, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code....Show more |
Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating PDF reports. If a report requests external resources plaintext credentials are in...Show more |
Elasticsearch Security versions 6.4.0 to 6.4.2 contain an error in the way request headers are applied to requests when using the Active Directory, LDAP, Native, or File realms. A request may receive headers intended for...Show more |
Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured via the API. The Elasticsearch _cluster/settings API, when queried, could leak sen...Show more |
2Elastic Redhat2Kibana Openshift Container PlatformNov 21, 2024 Sep 19, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Kibana versions 5.3.0 to 6.4.1 had a cross-site scripting (XSS) vulnerability via the source field formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of o...Show more |
1Elastic 1Elastic Cloud Enterprise Nov 21, 2024 Sep 19, 2018 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invalid roles token. An attacker with access to the previous runner ID and IP addres...Show more |
1Elastic 1Elastic Cloud Enterprise Nov 21, 2024 Sep 19, 2018 N/A· v4 7.5 HIGH· v3 3.5 LOW· v2 Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exception conditions would result in encryption keys, passwords, and other security sen...Show more |
A sensitive data disclosure flaw was found in the Elasticsearch repository-azure (formerly elasticsearch-cloud-azure) plugin. When the repository-azure plugin is set to log at TRACE level Azure credentials can be inadver...Show more |
In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameters are set using the _snapshot API they can be exposed as plain text by users...Show more |
1Elastic 1Elastic Cloud Enterprise Nov 21, 2024 Sep 19, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 a default master encryption key is used in the process of granting ZooKeeper access to Elasticsearch clusters. Unless explicitly overwritten, this master key is p...Show more |
1Elastic 3Elasticsearch X Pack Kibana X PackLogstash X PackNov 21, 2024 Sep 19, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. If an attacker is able to inject data into an index that has a ML job running against it, then when another user vie...Show more |
1Elastic 3Elasticsearch X Pack Kibana X PackLogstash X PackNov 21, 2024 Sep 19, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. Users with manage_ml permissions could create jobs containing malicious data as part of their configuration that cou...Show more |