Vulnerability index

Browse CVEs

221 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Kibana MEDIUM 5.4
CVE-2020-7015

Kibana versions before 6.8.9 and 7.7.0 contains a stored XSS flaw in the TSVB visualization. An attacker who is able to edit or create a TSVB visuali…

Fix: 6.8.10 / 7.7.1+
Fix from $1,600 2020-06-03
Kibana HIGH 8.8
CVE-2020-7012EPSS 18%

Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authenticated attacker with privile…

Fix: after 7.6.2
Fix from $1,950 2020-06-03
Elastic Cloud On Kubernetes HIGH 7.5
CVE-2020-7010

Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator. If an attacker is able to determin…

Fix: 1.1.0+
Fix from $1,950 2020-06-03
Kibana HIGH 7.2
CVE-2020-7013

Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualiza…

Fix: 6.8.9 / 7.7.0+
Fix from $1,950 2020-06-03
Elastic App Search MEDIUM 6.1
CVE-2020-7011

Elastic App Search versions before 7.7.0 contain a cross site scripting (XSS) flaw when displaying document URLs in the Reference UI. If the Referenc…

Fix: 7.7.0+
Fix from $1,600 2020-06-03
Elasticsearch HIGH 8.8
CVE-2020-7009

Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. …

Fix: 6.8.8 / 7.6.2+
Fix from $1,950 2020-03-31
Kibana MEDIUM 5.4
CVE-2019-7621

Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with th…

Fix: 6.8.6 / 7.5.1+
Fix from $1,600 2019-12-18
Logstash HIGH 7.5
CVE-2019-7620

Logstash versions before 7.4.1 and 6.8.4 contain a denial of service flaw in the Logstash Beats input plugin. An unauthenticated user who is able to …

Fix: 6.8.4 / 7.4.1+
Fix from $1,950 2019-10-30
Elasticsearch MEDIUM 5.3
CVE-2019-7619

Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker c…

Fix: after 7.3.2
Fix from $1,600 2019-10-30
Kibana MEDIUM 6.5
CVE-2019-7618

A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is p…

Mitigation only
Fix from $1,600 2019-10-01
Apm Agent HIGH 7.2
CVE-2019-7617

When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw if a remote attacker can cont…

Fix: 5.1.0+
Fix from $1,950 2019-08-22
Apm Agent Ruby HIGH 7.4
CVE-2019-7615

A TLS certificate validation flaw was found in Elastic APM agent for Ruby versions before 2.9.0. When specifying a trusted server CA certificate via …

Fix: 2.9.0+
Fix from $1,950 2019-07-30
Elasticsearch MEDIUM 5.9
CVE-2019-7614

A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple…

Fix: 6.8.2 / 7.2.1+
Fix from $1,600 2019-07-30
Kibana CRITICAL 10.0
CVE-2019-7609 KEVEPSS 95%

Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion …

Fix: 5.6.15 / 6.6.1+
Fix from $2,300 2019-03-25
Logstash CRITICAL 9.8
CVE-2019-7612

A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified …

Fix: 5.6.15 / 6.6.1+
Fix from $2,300 2019-03-25
Kibana CRITICAL 9.0
CVE-2019-7610

Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.securi…

Fix: 5.6.15 / 6.6.1+
Fix from $2,300 2019-03-25
Elasticsearch HIGH 8.1
CVE-2019-7611

A permission issue was found in Elasticsearch versions before 5.6.15 and 6.6.1 when Field Level Security and Document Level Security are disabled and…

Fix: 5.6.15 / 6.6.1+
Fix from $1,950 2019-03-25
Winlogbeat HIGH 7.5
CVE-2019-7613

Winlogbeat versions before 5.6.16 and 6.6.2 had an insufficient logging flaw. An attacker able to inject certain characters into a log entry could pr…

Fix: 5.6.16 / 6.6.2+
Fix from $1,950 2019-03-25
Kibana MEDIUM 6.1
CVE-2019-7608

Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XSS) vulnerability that could allow an attacker to obtain sensitive information f…

Fix: 5.6.15 / 6.6.1+
Fix from $1,600 2019-03-25
Kibana CRITICAL 9.8
CVE-2018-17245

Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating PDF report…

Fix: after 6.4.2
Fix from $2,300 2018-12-20
Kibana CRITICAL 9.8
CVE-2018-17246EPSS 82%

Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console…

Fix: 5.6.13 / 6.4.3+
Fix from $2,300 2018-12-20
Elasticsearch MEDIUM 6.5
CVE-2018-17244

Elasticsearch Security versions 6.4.0 to 6.4.2 contain an error in the way request headers are applied to requests when using the Active Directory, L…

Fix: after 6.4.2
Fix from $1,600 2018-12-20
Elasticsearch MEDIUM 5.9
CVE-2018-17247

Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a policy allowing external netw…

Mitigation only
Fix from $1,600 2018-12-20
Elasticsearch HIGH 8.8
CVE-2018-3831

Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured via the API…

Fix: 5.6.12 / 6.4.1+
Fix from $1,950 2018-09-19
Kibana MEDIUM 6.1
CVE-2018-3830

Kibana versions 5.3.0 to 6.4.1 had a cross-site scripting (XSS) vulnerability via the source field formatter that could allow an attacker to obtain s…

Fix: after 6.4.1
Fix from $1,600 2018-09-19
Elastic Cloud Enterprise MEDIUM 5.3
CVE-2018-3829

In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invalid roles…

Fix: 1.1.4+
Fix from $1,600 2018-09-19
Azure Repository HIGH 8.1
CVE-2018-3827

A sensitive data disclosure flaw was found in the Elasticsearch repository-azure (formerly elasticsearch-cloud-azure) plugin. When the repository-azu…

Fix: after 6.2.4
Fix from $1,950 2018-09-19
Elastic Cloud Enterprise HIGH 7.5
CVE-2018-3828

Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exception condit…

Fix: 1.1.4+
Fix from $1,950 2018-09-19
Elasticsearch MEDIUM 6.5
CVE-2018-3826

In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameters are …

Fix: after 6.2.4
Fix from $1,600 2018-09-19
Elasticsearch X Pack MEDIUM 6.1
CVE-2018-3824

X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. If an attacker is able to inject data into an…

Fix: 5.6.9 / 6.2.4+
Fix from $1,600 2018-09-19