Vulnerability index

Browse CVEs

221 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Elastic Cloud Enterprise MEDIUM 5.9
CVE-2018-3825

In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 a default master encryption key is used in the process of granting ZooKeeper access to Elas…

Fix: 1.1.4+
Fix from $1,600 2018-09-19
Elasticsearch X Pack MEDIUM 5.4
CVE-2018-3823

X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. Users with manage_ml permissions could create…

Fix: 5.6.9 / 6.2.4+
Fix from $1,600 2018-09-19
X Pack CRITICAL 9.8
CVE-2018-3822

X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM traversal. …

Mitigation only
Fix from $2,300 2018-03-30
Logstash MEDIUM 6.5
CVE-2018-3817

When logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log sensitive information.

Fix: 5.6.6 / 6.1.2+
Fix from $1,600 2018-03-30
Kibana MEDIUM 6.1
CVE-2018-3818

Kibana versions 5.1.1 to 6.1.2 and 5.6.6 had a cross-site scripting (XSS) vulnerability via the colored fields formatter that could allow an attacker…

Fix: after 6.1.2
Fix from $1,600 2018-03-30
Kibana MEDIUM 6.1
CVE-2018-3819

The fix in Kibana for ESA-2017-23 was incomplete. With X-Pack security enabled, Kibana versions before 6.1.3 and 5.6.7 have an open redirect vulnerab…

Fix: 5.6.7 / 6.1.3+
Fix from $1,600 2018-03-30
Kibana MEDIUM 6.1
CVE-2018-3820

Kibana versions after 6.1.0 and before 6.1.3 had a cross-site scripting (XSS) vulnerability in labs visualizations that could allow an attacker to ob…

Fix: 6.1.3+
Fix from $1,600 2018-03-30
Kibana MEDIUM 6.1
CVE-2018-3821

Kibana versions after 5.1.1 and before 5.6.7 and 6.1.3 had a cross-site scripting (XSS) vulnerability in the tag cloud visualization that could allow…

Fix: 5.6.7 / 6.1.3+
Fix from $1,600 2018-03-30
Elasticsearch CRITICAL 9.8
CVE-2015-5377EPSS 14%

Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI app…

Fix: 1.6.1+
Fix from $2,300 2018-03-06
Kibana MEDIUM 6.1
CVE-2017-11481

Kibana versions prior to 6.0.1 and 5.6.5 had a cross-site scripting (XSS) vulnerability via URL fields that could allow an attacker to obtain sensiti…

Mitigation only
Fix from $1,600 2017-12-08
Kibana MEDIUM 6.1
CVE-2017-11482

The Kibana fix for CVE-2017-8451 was found to be incomplete. With X-Pack installed, Kibana versions before 6.0.1 and 5.6.5 have an open redirect vuln…

Mitigation only
Fix from $1,600 2017-12-08
X Pack HIGH 8.8
CVE-2017-8448

An error was found in the permission model used by X-Pack Alerting 5.0.0 to 5.6.0 whereby users mapped to certain built-in roles could create a watch…

Mitigation only
Fix from $1,950 2017-09-29
X Pack MEDIUM 6.5
CVE-2017-8447

An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index' permissions on an index in a…

Mitigation only
Fix from $1,600 2017-09-29
Kibana MEDIUM 6.1
CVE-2017-11479

Kibana versions prior to 5.6.1 had a cross-site scripting (XSS) vulnerability in Timelion that could allow an attacker to obtain sensitive informatio…

Mitigation only
Fix from $1,600 2017-09-29
X Pack MEDIUM 5.5
CVE-2017-8445

An error was found in the X-Pack Security TLS trust manager for versions 5.0.0 to 5.5.1. If reloading the trust material fails the trust manager will…

Fix: after 5.5.1
Fix from $1,600 2017-08-18
Logstash MEDIUM 5.9
CVE-2015-5619

Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the L…

No fix yet
Fix from $1,600 2017-08-09
X Pack MEDIUM 6.5
CVE-2017-8442

Elasticsearch X-Pack Security versions 5.0.0 to 5.4.3, when enabled, can result in the Elasticsearch _nodes API leaking sensitive configuration infor…

Fix: after 5.4.3
Fix from $1,600 2017-07-07
Kibana MEDIUM 6.5
CVE-2017-8443

In Kibana X-Pack security versions prior to 5.4.3 if a Kibana user opens a crafted Kibana URL the result could be a redirect to an improperly initial…

Fix: after 5.4.2
Fix from $1,600 2017-06-30
Logstash HIGH 7.5
CVE-2015-5378

Logstash 1.5.x before 1.5.3 and 1.4.x before 1.4.4 allows remote attackers to read communications between Logstash Forwarder agent and Logstash serve…

No fix yet
Fix from $1,950 2017-06-27
Kibana Reporting HIGH 8.8
CVE-2016-1000218

Kibana Reporting plugin version 2.4.0 is vulnerable to a CSRF vulnerability that could allow an attacker to generate superfluous reports whenever an …

Mitigation only
Fix from $1,950 2017-06-16
Kibana HIGH 7.5
CVE-2016-1000219

Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers could be written to the log files…

Fix: 4.1.11 / 4.5.4+
Fix from $1,950 2017-06-16
Logstash HIGH 7.5
CVE-2016-1000221

Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could contain sensitive information.

Fix: after 2.3.3
Fix from $1,950 2017-06-16
Logstash HIGH 7.5
CVE-2016-1000222

Logstash prior to version 2.1.2, the CSV output can be attacked via engineered input that will create malicious formulas in the CSV data.

Fix: after 2.1.1
Fix from $1,950 2017-06-16
Logstash HIGH 7.5
CVE-2016-10363

Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, Netflow v9 or IPFIX packets c…

Fix: after 2.3.2
Fix from $1,950 2017-06-16
X Pack HIGH 7.5
CVE-2017-8450

X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users without access to a document an…

Mitigation only
Fix from $1,950 2017-06-16
Kibana HIGH 7.5
CVE-2017-8452

Kibana versions prior to 5.2.1 configured for SSL client access, file descriptors will fail to be cleaned up after certain requests and will accumula…

Fix: after 5.2.0
Fix from $1,950 2017-06-16
Kibana MEDIUM 6.5
CVE-2016-10364

With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any …

Mitigation only
Fix from $1,600 2017-06-16
Kibana MEDIUM 6.1
CVE-2015-9056

Kibana versions prior to 4.1.3 and 4.2.1 are vulnerable to a XSS attack.

Fix: 4.1.3 / 4.2.1+
Fix from $1,600 2017-06-16
Kibana MEDIUM 6.1
CVE-2016-1000220

Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScript in users' browsers.

Fix: 4.1.11 / 4.5.4+
Fix from $1,600 2017-06-16
Kibana MEDIUM 6.1
CVE-2016-10365

Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link in the Kibana domain that re…

Fix: after 5.0.0
Fix from $1,600 2017-06-16