Vulnerability index

Browse CVEs

221 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Elasticsearch MEDIUM 6.5
CVE-2024-23445

It was identified that if a cross-cluster API key https://www.elastic.co/guide/en/elasticsearch/reference/8.14/security-api-create-cross-cluster-api…

Fix: 8.14.0+
Fix from $1,600 2024-06-12
Elasticsearch MEDIUM 5.3
CVE-2024-23449

An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs when an encrypted PDF is passed to an attachment processor through the REST API. …

Fix: 8.11.1+
Fix from $1,600 2024-03-29
Elasticsearch MEDIUM 6.5
CVE-2024-23451

Incorrect Authorization issue exists in the API key based security model for Remote Cluster Security, which is currently in Beta, in Elasticsearch 8.…

Fix: 8.13.0+
Fix from $1,600 2024-03-27
Elasticsearch HIGH 7.5
CVE-2024-23450

A flaw was discovered in Elasticsearch, where processing a document in a deeply nested pipeline on an ingest node could cause the Elasticsearch node …

Fix: 7.17.19 / 8.13.0+
Fix from $1,950 2024-03-27
Apm Server HIGH 7.5
CVE-2024-23448

An issue was discovered whereby APM Server could log at ERROR level, a response from Elasticsearch indicating that indexing the document failed and t…

Fix: 8.12.1+
Fix from $1,950 2024-02-07
Kibana MEDIUM 6.5
CVE-2024-23446

An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DLS) or Field-level security (F…

Fix: 8.12.1+
Fix from $1,600 2024-02-07
Network Drive Connector MEDIUM 6.5
CVE-2024-23447

An issue was discovered in the Windows Network Drive Connector when using Document Level Security to assign permissions to a file, with explicit allo…

Fix: 8.12.1+
Fix from $1,600 2024-02-07
Kibana MEDIUM 6.5
CVE-2023-46675

An issue was discovered by Elastic whereby sensitive information may be recorded in Kibana logs in the event of an error or in the event where debug …

Fix: 7.17.16 / 8.11.2+
Fix from $1,600 2023-12-13
Kibana MEDIUM 6.5
CVE-2023-46671

An issue was discovered by Elastic whereby sensitive information may be recorded in Kibana logs in the event of an error. Elastic has released Kibana…

Fix: 8.11.1+
Fix from $1,600 2023-12-13
Elastic Beats MEDIUM 6.5
CVE-2023-49922

An issue was discovered by Elastic whereby Beats and Elastic Agent would log a raw event in its own logs at the WARN or ERROR level if ingesting that…

Fix: 7.17.16 / 8.11.3+
Fix from $1,600 2023-12-12
Elastic Agent MEDIUM 6.5
CVE-2023-6687

An issue was discovered by Elastic whereby Elastic Agent would log a raw event in its own logs at the WARN or ERROR level if ingesting that event to …

Fix: 7.17.16 / 8.11.3+
Fix from $1,600 2023-12-12
Enterprise Search MEDIUM 6.5
CVE-2023-49923

An issue was discovered by Elastic whereby the Documents API of App Search logged the raw contents of indexed documents at INFO log level. Depending …

Fix: 7.17.16 / 8.11.2+
Fix from $1,600 2023-12-12
Elasticsearch HIGH 7.8
CVE-2023-46674

An issue was identified that allowed the unsafe deserialization of java objects from hadoop or spark configuration properties that could have been mo…

Fix: 7.17.11 / 8.9.0+
Fix from $1,950 2023-12-05
Elasticsearch HIGH 7.5
CVE-2023-46673

It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling t…

Fix: 7.17.14 / 8.10.3+
Fix from $1,950 2023-11-22
Elasticsearch HIGH 8.8
CVE-2021-37937

An issue was found with how API keys are created with the Fleet-Server service account. When an API key is created with a service account, it is poss…

Fix: after 7.14.0
Fix from $1,950 2023-11-22
Apm Java Agent HIGH 7.8
CVE-2021-37942

A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious plugin to an application ru…

Fix: after 1.27.0
Fix from $1,950 2023-11-22
Kibana HIGH 8.8
CVE-2021-22142

Kibana contains an embedded version of the Chromium browser that the Reporting feature uses to generate the downloadable reports. If a user with perm…

Fix: 7.13.0+
Fix from $1,950 2023-11-22
Kibana HIGH 7.2
CVE-2021-22150

It was discovered that a user with Fleet admin permissions could upload a malicious package. Due to using an older version of the js-yaml library, th…

Fix: 7.14.1+
Fix from $1,950 2023-11-22
Logstash MEDIUM 5.5
CVE-2023-46672

An issue was identified by Elastic whereby sensitive information is recorded in Logstash logs under specific circumstances. The prerequisites for th…

Fix: 8.11.1+
Fix from $1,600 2023-11-15
Elastic Cloud On Kubernetes MEDIUM 5.3
CVE-2023-31416

Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requests to an APM Server being a…

Fix: 2.8+
Fix from $1,600 2023-10-26
Elasticsearch HIGH 7.5
CVE-2023-31418

An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch…

Fix: after 8.8.2
Fix from $1,950 2023-10-26
Elasticsearch HIGH 7.5
CVE-2023-31419EPSS 61%

A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimat…

Fix: after 8.9.0
Fix from $1,950 2023-10-26
Elastic Sharepoint Online Python Connector MEDIUM 6.5
CVE-2023-46666

An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python Connector. …

Fix: 8.10.3.0+
Fix from $1,600 2023-10-26
Elastic Beats HIGH 7.5
CVE-2023-31421

It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whether the server certificate i…

Fix: after 8.9.2
Fix from $1,950 2023-10-26
Kibana HIGH 7.5
CVE-2023-31422

An issue was discovered by Elastic whereby sensitive information is recorded in Kibana logs in the event of an error. The issue impacts only Kibana v…

Mitigation only
Fix from $1,950 2023-10-26
Fleet Server HIGH 8.1
CVE-2023-46667

An issue was discovered in Fleet Server >= v8.10.0 and < v8.10.3 where Agent enrolment tokens are being inserted into the Fleet Server’s log file in …

Fix: 8.10.3+
Fix from $1,950 2023-10-26
Endpoint CRITICAL 9.1
CVE-2023-46668

If Elastic Endpoint (v7.9.0 - v8.10.3) is configured to use a non-default option in which the logging level is explicitly set to debug, and when Elas…

Fix: after 8.10.3
Fix from $2,300 2023-10-26
Kibana HIGH 8.8
CVE-2023-31414

Kibana versions 8.0.0 through 8.7.0 contain an arbitrary code execution flaw. An attacker with write access to Kibana yaml or env configuration could…

Fix: after 8.7.0
Fix from $1,950 2023-05-04
Kibana HIGH 8.8
CVE-2023-31415

Kibana version 8.7.0 contains an arbitrary code execution flaw. An attacker with All privileges to the Uptime/Synthetics feature could send a request…

Mitigation only
Fix from $1,950 2023-05-04
Kibana MEDIUM 6.1
CVE-2022-38779

An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted …

Fix: 7.17.9 / 8.6.2+
Fix from $1,600 2023-02-22