← Back

Elastic

elastic

341 CVEs • 32 products

Products (32)

Click to collapse
Toggle
Kibana
kibana
Elasticsearch
elasticsearch
Logstash
logstash
X Pack
x-pack
Elastic Agent
elastic_agent
Fleet Server
fleet_server
Apm Server
apm_server
Apm Agent
apm_agent
Filebeat
filebeat
Kibana X Pack
kibana_x-pack
Endgame
endgame
Elastic Beats
elastic_beats
Winlogbeat
winlogbeat
Apm Agent Ruby
apm-agent-ruby
Endpoint
endpoint
Apm .net Agent
apm_.net_agent
Apm Java Agent
apm_java_agent
Metricbeat
metricbeat
Maps Server
maps_server

CVEs (341)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Elastic
1Elasticsearch
Jun 17, 2026
Jul 30, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gai...Show more
A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gain access to response header containing sensitive data from another user.Show less
1Elastic
1Winlogbeat
Jun 17, 2026
Mar 25, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Winlogbeat versions before 5.6.16 and 6.6.2 had an insufficient logging flaw. An attacker able to inject certain characters into a log entry could prevent Winlogbeat from recording the event.
2Elastic
Netapp
2Active Iq Performance Analytics Services
Logstash
Jun 17, 2026
Mar 25, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified as part of the Logstash configuration, the credentials for the URL coul...Show more
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified as part of the Logstash configuration, the credentials for the URL could be inadvertently logged as part of the error message.Show less
1Elastic
1Elasticsearch
Jun 17, 2026
Mar 25, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
A permission issue was found in Elasticsearch versions before 5.6.15 and 6.6.1 when Field Level Security and Document Level Security are disabled and the _aliases, _shrink, or _split endpoints are used . If the elasticse...Show more
A permission issue was found in Elasticsearch versions before 5.6.15 and 6.6.1 when Field Level Security and Document Level Security are disabled and the _aliases, _shrink, or _split endpoints are used . If the elasticsearch.yml file has xpack.security.dls_fls.enabled set to false, certain permission checks are skipped when users perform one of the actions mentioned above, to make existing data available under a new index/alias name. This could result in an attacker gaining additional permissions against a restricted index.Show less
1Elastic
1Kibana
Jun 17, 2026
Mar 25, 2019
N/A· v4
9.0 CRITICAL· v3
9.3 HIGH· v2
Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.security.audit.enabled set to true, an attacker could send a request that wil...Show more
Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.security.audit.enabled set to true, an attacker could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.Show less
2Elastic
Redhat
2Kibana
Openshift Container Platform
Jun 17, 2026
Mar 25, 2019
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascrip...Show more
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.Show less
1Elastic
1Kibana
Jun 17, 2026
Mar 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XSS) vulnerability that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
1Elastic
1Elasticsearch
Nov 21, 2024
Dec 20, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a policy allowing external network access has been added to Elasticsearch's Java Security Manager then...Show more
Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a policy allowing external network access has been added to Elasticsearch's Java Security Manager then an attacker could send a specially crafted request capable of leaking content of local files on the Elasticsearch node. This could allow a user to access information that they should not have access to.Show less
2Elastic
Redhat
2Kibana
Openshift Container Platform
Nov 21, 2024
Dec 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code....Show more
Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.Show less
1Elastic
1Kibana
Nov 21, 2024
Dec 20, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating PDF reports. If a report requests external resources plaintext credentials are in...Show more
Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating PDF reports. If a report requests external resources plaintext credentials are included in the HTTP request that could be recovered by an external resource provider.Show less
1Elastic
1Elasticsearch
Nov 21, 2024
Dec 20, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Elasticsearch Security versions 6.4.0 to 6.4.2 contain an error in the way request headers are applied to requests when using the Active Directory, LDAP, Native, or File realms. A request may receive headers intended for...Show more
Elasticsearch Security versions 6.4.0 to 6.4.2 contain an error in the way request headers are applied to requests when using the Active Directory, LDAP, Native, or File realms. A request may receive headers intended for another request if the same username is being authenticated concurrently; when used with run as, this can result in the request running as the incorrect user. This could allow a user to access information that they should not have access to.Show less
1Elastic
1Elasticsearch
Nov 21, 2024
Sep 19, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured via the API. The Elasticsearch _cluster/settings API, when queried, could leak sen...Show more
Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured via the API. The Elasticsearch _cluster/settings API, when queried, could leak sensitive configuration information such as passwords, tokens, or usernames. This could allow an authenticated Elasticsearch user to improperly view these details.Show less
2Elastic
Redhat
2Kibana
Openshift Container Platform
Nov 21, 2024
Sep 19, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Kibana versions 5.3.0 to 6.4.1 had a cross-site scripting (XSS) vulnerability via the source field formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of o...Show more
Kibana versions 5.3.0 to 6.4.1 had a cross-site scripting (XSS) vulnerability via the source field formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.Show less
1Elastic
1Elastic Cloud Enterprise
Nov 21, 2024
Sep 19, 2018
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invalid roles token. An attacker with access to the previous runner ID and IP addres...Show more
In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invalid roles token. An attacker with access to the previous runner ID and IP address of the coordinator-host could add a allocator to an existing ECE install to gain access to other clusters data.Show less
1Elastic
1Elastic Cloud Enterprise
Nov 21, 2024
Sep 19, 2018
N/A· v4
7.5 HIGH· v3
3.5 LOW· v2
Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exception conditions would result in encryption keys, passwords, and other security sen...Show more
Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exception conditions would result in encryption keys, passwords, and other security sensitive headers being leaked to the allocator logs. An attacker with access to the logging cluster may obtain leaked credentials and perform authenticated actions using these credentials.Show less
1Elastic
1Azure Repository
Nov 21, 2024
Sep 19, 2018
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
A sensitive data disclosure flaw was found in the Elasticsearch repository-azure (formerly elasticsearch-cloud-azure) plugin. When the repository-azure plugin is set to log at TRACE level Azure credentials can be inadver...Show more
A sensitive data disclosure flaw was found in the Elasticsearch repository-azure (formerly elasticsearch-cloud-azure) plugin. When the repository-azure plugin is set to log at TRACE level Azure credentials can be inadvertently logged.Show less
1Elastic
1Elasticsearch
Nov 21, 2024
Sep 19, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameters are set using the _snapshot API they can be exposed as plain text by users...Show more
In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameters are set using the _snapshot API they can be exposed as plain text by users able to query the _snapshot API.Show less
1Elastic
1Elastic Cloud Enterprise
Nov 21, 2024
Sep 19, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 a default master encryption key is used in the process of granting ZooKeeper access to Elasticsearch clusters. Unless explicitly overwritten, this master key is p...Show more
In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 a default master encryption key is used in the process of granting ZooKeeper access to Elasticsearch clusters. Unless explicitly overwritten, this master key is predictable across all ECE deployments. If an attacker can connect to ZooKeeper directly they would be able to access configuration information of other tenants if their cluster ID is known.Show less
1Elastic
3Elasticsearch X Pack
Kibana X PackLogstash X Pack
Nov 21, 2024
Sep 19, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. If an attacker is able to inject data into an index that has a ML job running against it, then when another user vie...Show more
X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. If an attacker is able to inject data into an index that has a ML job running against it, then when another user views the results of the ML job it could allow the attacker to obtain sensitive information from or perform destructive actions on behalf of that other ML user.Show less
1Elastic
3Elasticsearch X Pack
Kibana X PackLogstash X Pack
Nov 21, 2024
Sep 19, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. Users with manage_ml permissions could create jobs containing malicious data as part of their configuration that cou...Show more
X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. Users with manage_ml permissions could create jobs containing malicious data as part of their configuration that could allow the attacker to obtain sensitive information from or perform destructive actions on behalf of other ML users viewing the results of the jobs.Show less