← Back

Elasticsearch

elasticsearch

20 CVEs • 8 products

Products (8)

Click to collapse
Toggle
Packetbeat
packetbeat
Elasticsearch
elasticsearch
Logstash
logstash
Kibana
kibana
Output Plugin
output_plugin
X Pack
x-pack

CVEs (20)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Elasticsearch
1Packetbeat
Jun 17, 2026
Mar 19, 2026
N/A· v4
5.7 MEDIUM· v3
N/A· v2
Improper Validation of Array Index (CWE-129) in multiple protocol parser components in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker with the ability to send specially crafted...Show more
Improper Validation of Array Index (CWE-129) in multiple protocol parser components in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker with the ability to send specially crafted, malformed network packets to a monitored network interface can trigger out-of-bounds read operations, resulting in application crashes or resource exhaustion. This requires the attacker to be positioned on the same network segment as the Packetbeat deployment or to control traffic routed to monitored interfaces.Show less
1Elasticsearch
1Packetbeat
Jun 17, 2026
Feb 26, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper Validation of Array Index (CWE-129) in the PostgreSQL protocol parser in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker can send a specially crafted packet causing a G...Show more
Improper Validation of Array Index (CWE-129) in the PostgreSQL protocol parser in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker can send a specially crafted packet causing a Go runtime panic that terminates the Packetbeat process. This vulnerability requires the pgsql protocol to be explicitly enabled and configured to monitor traffic on the targeted port.Show less
1Elasticsearch
1Packetbeat
Jun 17, 2026
Dec 18, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEC-130) of memory and CPU via the integration of malicious IPv4 fragments, leadin...Show more
Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEC-130) of memory and CPU via the integration of malicious IPv4 fragments, leading to a degradation in Packetbeat.Show less
1Elasticsearch
1Packetbeat
Jun 17, 2026
Dec 18, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Out-of-bounds read (CWE-125) allows an unauthenticated remote attacker to perform a buffer overflow (CAPEC-100) via the NFS protocol dissector, leading to a denial-of-service (DoS) through a reliable process crash when h...Show more
Out-of-bounds read (CWE-125) allows an unauthenticated remote attacker to perform a buffer overflow (CAPEC-100) via the NFS protocol dissector, leading to a denial-of-service (DoS) through a reliable process crash when handling truncated XDR-encoded RPC messages.Show less
1Elasticsearch
1Packetbeat
Jun 17, 2026
Dec 18, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper Bounds Check (CWE-787) in Packetbeat can allow a remote unauthenticated attacker to exploit a Buffer Overflow (CAPEC-100) and reliably crash the application or cause significant resource exhaustion via a single...Show more
Improper Bounds Check (CWE-787) in Packetbeat can allow a remote unauthenticated attacker to exploit a Buffer Overflow (CAPEC-100) and reliably crash the application or cause significant resource exhaustion via a single crafted UDP packet with an invalid fragment sequence number.Show less
2Elasticsearch
Oracle
4Communications Billing And Revenue Management
Communications Cloud Native Core Network Function Cloud Native EnvironmentKibana+1 more
Jun 17, 2026
Jul 27, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive information or perform de...Show more
In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive information or perform destructive actions on behalf of Kibana users who view the region map visualization.Show less
2Elasticsearch
Oracle
4Communications Billing And Revenue Management
Communications Cloud Native Core Network Function Cloud Native EnvironmentKibana+1 more
Jun 17, 2026
Jul 27, 2020
N/A· v4
4.8 MEDIUM· v3
2.1 LOW· v2
Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consuming large amounts of CPU...Show more
Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consuming large amounts of CPU and becoming unresponsive.Show less
1Elasticsearch
1Packetbeat
May 13, 2026
Dec 8, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Packetbeat versions prior to 5.6.4 are affected by a denial of service flaw in the PostgreSQL protocol handler. If Packetbeat is listening for PostgreSQL traffic and a user is able to send arbitrary network traffic to th...Show more
Packetbeat versions prior to 5.6.4 are affected by a denial of service flaw in the PostgreSQL protocol handler. If Packetbeat is listening for PostgreSQL traffic and a user is able to send arbitrary network traffic to the monitored port, the attacker could prevent Packetbeat from properly logging other PostgreSQL traffic.Show less
1Elasticsearch
1Cloud Enterprise
May 13, 2026
Sep 29, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The client-forwarder in Elastic Cloud Enterprise versions prior to 1.0.2 do not properly encrypt traffic to ZooKeeper. If an attacker is able to man in the middle (MITM) the traffic between the client-forwarder and ZooKe...Show more
The client-forwarder in Elastic Cloud Enterprise versions prior to 1.0.2 do not properly encrypt traffic to ZooKeeper. If an attacker is able to man in the middle (MITM) the traffic between the client-forwarder and ZooKeeper they could potentially obtain sensitive data.Show less
2Elastic
Elasticsearch
2Kibana
Kibana
May 13, 2026
Sep 29, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Kibana versions prior to 5.6.1 had a cross-site scripting (XSS) vulnerability in Timelion that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
1Elasticsearch
1Logstash
May 13, 2026
Sep 25, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls for user-writable directory trees, which allows local users to gain privileges by leveraging access to...Show more
The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls for user-writable directory trees, which allows local users to gain privileges by leveraging access to a $LS_USER account for creation of a hard link.Show less
1Elasticsearch
2X Pack
X Pack Reporting
May 13, 2026
Aug 18, 2017
N/A· v4
5.3 MEDIUM· v3
4.0 MEDIUM· v2
The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vulnerability. A user with the reporting_user role could execute a report w...Show more
The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vulnerability. A user with the reporting_user role could execute a report with the permissions of another reporting user, possibly gaining access to sensitive data.Show less
2Elastic
Elasticsearch
2Logstash
Logstash
May 13, 2026
Aug 9, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might allow attackers to obtain sensitive informa...Show more
Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might allow attackers to obtain sensitive information via a man-in-the-middle attack.Show less
1Elasticsearch
1Elasticsearch
May 13, 2026
Aug 9, 2017
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
The snapshot API in Elasticsearch before 1.6.0 when another application exists on the system that can read Lucene files and execute code from them, is accessible by the attacker, and the Java VM on which Elasticsearch is...Show more
The snapshot API in Elasticsearch before 1.6.0 when another application exists on the system that can read Lucene files and execute code from them, is accessible by the attacker, and the Java VM on which Elasticsearch is running can write to a location that the other application can read and execute from, allows remote authenticated users to write to and create arbitrary snapshot metadata files, and potentially execute arbitrary code.Show less
2Elastic
Elasticsearch
2Logstash
Logstash
May 13, 2026
Jun 27, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Logstash 1.5.x before 1.5.3 and 1.4.x before 1.4.4 allows remote attackers to read communications between Logstash Forwarder agent and Logstash server.
1Elasticsearch
1Output Plugin
May 13, 2026
Jun 16, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file HTTP basic auth credentials.
1Elasticsearch
1Elasticsearch
May 6, 2026
Aug 17, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unspecified vectors related to snapshot API calls.
1Elasticsearch
1Elasticsearch
May 6, 2026
May 1, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors.
1Elasticsearch
1Elasticsearch
May 6, 2026
Oct 10, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the CORS functionality in Elasticsearch before 1.4.0.Beta1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
2Elastic
Elasticsearch
2Elasticsearch
Elasticsearch
Apr 22, 2026
Jul 28, 2014
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only vio...Show more
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.Show less