Vulnerability index

Browse CVEs

221 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2024-23445 It was identified that if a cross-cluster API key https://www.elastic.co/guide/en/elasticsearch/reference/8.14/security-api-create-cross-cluster-api… Elasticsearch 8.14.0+ Fix from $1,6002024-06-12 MEDIUM 5.3 CVE-2024-23449 An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs when an encrypted PDF is passed to an attachment processor through the REST API. … Elasticsearch 8.11.1+ Fix from $1,6002024-03-29 MEDIUM 6.5 CVE-2024-23451 Incorrect Authorization issue exists in the API key based security model for Remote Cluster Security, which is currently in Beta, in Elasticsearch 8.… Elasticsearch 8.13.0+ Fix from $1,6002024-03-27 HIGH 7.5 CVE-2024-23450 A flaw was discovered in Elasticsearch, where processing a document in a deeply nested pipeline on an ingest node could cause the Elasticsearch node … Elasticsearch 7.17.19 / 8.13.0+ Fix from $1,9502024-03-27 HIGH 7.5 CVE-2024-23448 An issue was discovered whereby APM Server could log at ERROR level, a response from Elasticsearch indicating that indexing the document failed and t… Apm Server 8.12.1+ Fix from $1,9502024-02-07 MEDIUM 6.5 CVE-2024-23446 An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DLS) or Field-level security (F… Kibana 8.12.1+ Fix from $1,6002024-02-07 MEDIUM 6.5 CVE-2024-23447 An issue was discovered in the Windows Network Drive Connector when using Document Level Security to assign permissions to a file, with explicit allo… Network Drive Connector 8.12.1+ Fix from $1,6002024-02-07 MEDIUM 6.5 CVE-2023-46675 An issue was discovered by Elastic whereby sensitive information may be recorded in Kibana logs in the event of an error or in the event where debug … Kibana 7.17.16 / 8.11.2+ Fix from $1,6002023-12-13 MEDIUM 6.5 CVE-2023-46671 An issue was discovered by Elastic whereby sensitive information may be recorded in Kibana logs in the event of an error. Elastic has released Kibana… Kibana 8.11.1+ Fix from $1,6002023-12-13 MEDIUM 6.5 CVE-2023-49922 An issue was discovered by Elastic whereby Beats and Elastic Agent would log a raw event in its own logs at the WARN or ERROR level if ingesting that… Elastic Beats 7.17.16 / 8.11.3+ Fix from $1,6002023-12-12 MEDIUM 6.5 CVE-2023-6687 An issue was discovered by Elastic whereby Elastic Agent would log a raw event in its own logs at the WARN or ERROR level if ingesting that event to … Elastic Agent 7.17.16 / 8.11.3+ Fix from $1,6002023-12-12 MEDIUM 6.5 CVE-2023-49923 An issue was discovered by Elastic whereby the Documents API of App Search logged the raw contents of indexed documents at INFO log level. Depending … Enterprise Search 7.17.16 / 8.11.2+ Fix from $1,6002023-12-12 HIGH 7.8 CVE-2023-46674 An issue was identified that allowed the unsafe deserialization of java objects from hadoop or spark configuration properties that could have been mo… Elasticsearch 7.17.11 / 8.9.0+ Fix from $1,9502023-12-05 HIGH 7.5 CVE-2023-46673 It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling t… Elasticsearch 7.17.14 / 8.10.3+ Fix from $1,9502023-11-22 HIGH 8.8 CVE-2021-37937 An issue was found with how API keys are created with the Fleet-Server service account. When an API key is created with a service account, it is poss… Elasticsearch after 7.14.0 Fix from $1,9502023-11-22 HIGH 7.8 CVE-2021-37942 A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious plugin to an application ru… Apm Java Agent after 1.27.0 Fix from $1,9502023-11-22 HIGH 8.8 CVE-2021-22142 Kibana contains an embedded version of the Chromium browser that the Reporting feature uses to generate the downloadable reports. If a user with perm… Kibana 7.13.0+ Fix from $1,9502023-11-22 HIGH 7.2 CVE-2021-22150 It was discovered that a user with Fleet admin permissions could upload a malicious package. Due to using an older version of the js-yaml library, th… Kibana 7.14.1+ Fix from $1,9502023-11-22 MEDIUM 5.5 CVE-2023-46672 An issue was identified by Elastic whereby sensitive information is recorded in Logstash logs under specific circumstances. The prerequisites for th… Logstash 8.11.1+ Fix from $1,6002023-11-15 MEDIUM 5.3 CVE-2023-31416 Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requests to an APM Server being a… Elastic Cloud On Kubernetes 2.8+ Fix from $1,6002023-10-26 HIGH 7.5 CVE-2023-31418 An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch… Elasticsearch after 8.8.2 Fix from $1,9502023-10-26 HIGH 7.5 CVE-2023-31419EPSS 61% A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimat… Elasticsearch after 8.9.0 Fix from $1,9502023-10-26 MEDIUM 6.5 CVE-2023-46666 An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python Connector. … Elastic Sharepoint Online Python Connector 8.10.3.0+ Fix from $1,6002023-10-26 HIGH 7.5 CVE-2023-31421 It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whether the server certificate i… Elastic Beats after 8.9.2 Fix from $1,9502023-10-26 HIGH 7.5 CVE-2023-31422 An issue was discovered by Elastic whereby sensitive information is recorded in Kibana logs in the event of an error. The issue impacts only Kibana v… Kibana Mitigation only Fix from $1,9502023-10-26 HIGH 8.1 CVE-2023-46667 An issue was discovered in Fleet Server >= v8.10.0 and < v8.10.3 where Agent enrolment tokens are being inserted into the Fleet Server’s log file in … Fleet Server 8.10.3+ Fix from $1,9502023-10-26 CRITICAL 9.1 CVE-2023-46668 If Elastic Endpoint (v7.9.0 - v8.10.3) is configured to use a non-default option in which the logging level is explicitly set to debug, and when Elas… Endpoint after 8.10.3 Fix from $2,3002023-10-26 HIGH 8.8 CVE-2023-31414 Kibana versions 8.0.0 through 8.7.0 contain an arbitrary code execution flaw. An attacker with write access to Kibana yaml or env configuration could… Kibana after 8.7.0 Fix from $1,9502023-05-04 HIGH 8.8 CVE-2023-31415 Kibana version 8.7.0 contains an arbitrary code execution flaw. An attacker with All privileges to the Uptime/Synthetics feature could send a request… Kibana Mitigation only Fix from $1,9502023-05-04 MEDIUM 6.1 CVE-2022-38779 An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted … Kibana 7.17.9 / 8.6.2+ Fix from $1,6002023-02-22