Vulnerability index

Browse CVEs

221 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Kibana MEDIUM 6.1
CVE-2016-10366

Kibana versions after and including 4.3 and before 4.6.2 are vulnerable to a cross-site scripting (XSS) attack.

Mitigation only
Fix from $1,600 2017-06-16
Kibana MEDIUM 6.1
CVE-2017-8451

With X-Pack installed, Kibana versions before 5.3.1 have an open redirect vulnerability on the login page that would enable an attacker to craft a li…

Fix: after 5.3.0
Fix from $1,600 2017-06-16
X Pack MEDIUM 5.9
CVE-2017-8449

X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules used a mix of grant and excl…

Fix: after 5.2.2
Fix from $1,600 2017-06-16
X Pack HIGH 8.8
CVE-2017-8438

Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality. This bug prevents transitioning into …

Patch available
Fix from $1,950 2017-06-05
Kibana MEDIUM 6.1
CVE-2017-8439

Kibana version 5.4.0 was affected by a Cross Site Scripting (XSS) bug in the Time Series Visual Builder. This bug could allow an attacker to obtain s…

Mitigation only
Fix from $1,600 2017-06-05
Kibana MEDIUM 6.1
CVE-2017-8440

Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow an attacker to obtain sensitiv…

Mitigation only
Fix from $1,600 2017-06-05
Kibana MEDIUM 6.8
CVE-2015-8131

Cross-site request forgery (CSRF) vulnerability in Elasticsearch Kibana before 4.1.3 and 4.2.x before 4.2.1 allows remote attackers to hijack the aut…

Fix: after 4.1.2
Fix from $1,600 2015-12-07
Logstash MEDIUM 6.4
CVE-2015-4152

Directory traversal vulnerability in the file output plugin in Elasticsearch Logstash before 1.4.3 allows remote attackers to write to arbitrary file…

Fix: after 1.4.2
Fix from $1,600 2015-06-15
Elasticsearch CRITICAL 9.8
CVE-2015-1427 KEVEPSS 100%

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism a…

Fix: 1.3.8 / 1.4.3+
Fix from $2,300 2015-02-17
Elasticsearch HIGH 8.1
CVE-2014-3120 KEVEPSS 89%

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions …

Fix: 1.2.0+
Fix from $1,950 2014-07-28
Logstash HIGH 7.5
CVE-2014-4326

Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows remote attackers to execute arbitrary commands via a crafted event in (1) zabbix.rb o…

Mitigation only
Fix from $1,950 2014-07-22