Elasticsearch
elasticsearch
20 CVEs • 8 products
Products (8)
Click to collapseToggle
Products (8)
Click to collapse
CVEs (20)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper Validation of Array Index (CWE-129) in multiple protocol parser components in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker with the ability to send specially crafted...Show more |
Improper Validation of Array Index (CWE-129) in the PostgreSQL protocol parser in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker can send a specially crafted packet causing a G...Show more |
Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEC-130) of memory and CPU via the integration of malicious IPv4 fragments, leadin...Show more |
Out-of-bounds read (CWE-125) allows an unauthenticated remote attacker to perform a buffer overflow (CAPEC-100) via the NFS protocol dissector, leading to a denial-of-service (DoS) through a reliable process crash when h...Show more |
Improper Bounds Check (CWE-787) in Packetbeat can allow a remote unauthenticated attacker to exploit a Buffer Overflow (CAPEC-100) and reliably crash the application or cause significant resource exhaustion via a single...Show more |
2Elasticsearch Oracle4Communications Billing And Revenue Management Communications Cloud Native Core Network Function Cloud Native EnvironmentKibana+1 moreJun 17, 2026 Jul 27, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive information or perform de...Show more |
2Elasticsearch Oracle4Communications Billing And Revenue Management Communications Cloud Native Core Network Function Cloud Native EnvironmentKibana+1 moreJun 17, 2026 Jul 27, 2020 N/A· v4 4.8 MEDIUM· v3 2.1 LOW· v2 Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consuming large amounts of CPU...Show more |
Packetbeat versions prior to 5.6.4 are affected by a denial of service flaw in the PostgreSQL protocol handler. If Packetbeat is listening for PostgreSQL traffic and a user is able to send arbitrary network traffic to th...Show more |
1Elasticsearch 1Cloud Enterprise May 13, 2026 Sep 29, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The client-forwarder in Elastic Cloud Enterprise versions prior to 1.0.2 do not properly encrypt traffic to ZooKeeper. If an attacker is able to man in the middle (MITM) the traffic between the client-forwarder and ZooKe...Show more |
2Elastic Elasticsearch2Kibana KibanaMay 13, 2026 Sep 29, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Kibana versions prior to 5.6.1 had a cross-site scripting (XSS) vulnerability in Timelion that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users. |
The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls for user-writable directory trees, which allows local users to gain privileges by leveraging access to...Show more |
1Elasticsearch 2X Pack X Pack ReportingMay 13, 2026 Aug 18, 2017 N/A· v4 5.3 MEDIUM· v3 4.0 MEDIUM· v2 The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vulnerability. A user with the reporting_user role could execute a report w...Show more |
2Elastic Elasticsearch2Logstash LogstashMay 13, 2026 Aug 9, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might allow attackers to obtain sensitive informa...Show more |
The snapshot API in Elasticsearch before 1.6.0 when another application exists on the system that can read Lucene files and execute code from them, is accessible by the attacker, and the Java VM on which Elasticsearch is...Show more |
2Elastic Elasticsearch2Logstash LogstashMay 13, 2026 Jun 27, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Logstash 1.5.x before 1.5.3 and 1.4.x before 1.4.4 allows remote attackers to read communications between Logstash Forwarder agent and Logstash server. |
1Elasticsearch 1Output Plugin May 13, 2026 Jun 16, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file HTTP basic auth credentials. |
Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unspecified vectors related to snapshot API calls. |
Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors. |
Cross-site scripting (XSS) vulnerability in the CORS functionality in Elasticsearch before 1.4.0.Beta1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
2Elastic Elasticsearch2Elasticsearch ElasticsearchApr 22, 2026 Jul 28, 2014 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only vio...Show more |