Vulnerability index

Browse CVEs

221 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2020-7015 Kibana versions before 6.8.9 and 7.7.0 contains a stored XSS flaw in the TSVB visualization. An attacker who is able to edit or create a TSVB visuali… Kibana 6.8.10 / 7.7.1+ Fix from $1,6002020-06-03 HIGH 8.8 CVE-2020-7012EPSS 18% Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authenticated attacker with privile… Kibana after 7.6.2 Fix from $1,9502020-06-03 HIGH 7.5 CVE-2020-7010 Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator. If an attacker is able to determin… Elastic Cloud On Kubernetes 1.1.0+ Fix from $1,9502020-06-03 HIGH 7.2 CVE-2020-7013 Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualiza… Kibana 6.8.9 / 7.7.0+ Fix from $1,9502020-06-03 MEDIUM 6.1 CVE-2020-7011 Elastic App Search versions before 7.7.0 contain a cross site scripting (XSS) flaw when displaying document URLs in the Reference UI. If the Referenc… Elastic App Search 7.7.0+ Fix from $1,6002020-06-03 HIGH 8.8 CVE-2020-7009 Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. … Elasticsearch 6.8.8 / 7.6.2+ Fix from $1,9502020-03-31 MEDIUM 5.4 CVE-2019-7621 Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with th… Kibana 6.8.6 / 7.5.1+ Fix from $1,6002019-12-18 HIGH 7.5 CVE-2019-7620 Logstash versions before 7.4.1 and 6.8.4 contain a denial of service flaw in the Logstash Beats input plugin. An unauthenticated user who is able to … Logstash 6.8.4 / 7.4.1+ Fix from $1,9502019-10-30 MEDIUM 5.3 CVE-2019-7619 Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker c… Elasticsearch after 7.3.2 Fix from $1,6002019-10-30 MEDIUM 6.5 CVE-2019-7618 A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is p… Kibana Mitigation only Fix from $1,6002019-10-01 HIGH 7.2 CVE-2019-7617 When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw if a remote attacker can cont… Apm Agent 5.1.0+ Fix from $1,9502019-08-22 HIGH 7.4 CVE-2019-7615 A TLS certificate validation flaw was found in Elastic APM agent for Ruby versions before 2.9.0. When specifying a trusted server CA certificate via … Apm Agent Ruby 2.9.0+ Fix from $1,9502019-07-30 MEDIUM 5.9 CVE-2019-7614 A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple… Elasticsearch 6.8.2 / 7.2.1+ Fix from $1,6002019-07-30 CRITICAL 10.0 CVE-2019-7609 KEVEPSS 95% Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion … Kibana 5.6.15 / 6.6.1+ Fix from $2,3002019-03-25 CRITICAL 9.8 CVE-2019-7612 A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified … Logstash 5.6.15 / 6.6.1+ Fix from $2,3002019-03-25 CRITICAL 9.0 CVE-2019-7610 Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.securi… Kibana 5.6.15 / 6.6.1+ Fix from $2,3002019-03-25 HIGH 8.1 CVE-2019-7611 A permission issue was found in Elasticsearch versions before 5.6.15 and 6.6.1 when Field Level Security and Document Level Security are disabled and… Elasticsearch 5.6.15 / 6.6.1+ Fix from $1,9502019-03-25 HIGH 7.5 CVE-2019-7613 Winlogbeat versions before 5.6.16 and 6.6.2 had an insufficient logging flaw. An attacker able to inject certain characters into a log entry could pr… Winlogbeat 5.6.16 / 6.6.2+ Fix from $1,9502019-03-25 MEDIUM 6.1 CVE-2019-7608 Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XSS) vulnerability that could allow an attacker to obtain sensitive information f… Kibana 5.6.15 / 6.6.1+ Fix from $1,6002019-03-25 CRITICAL 9.8 CVE-2018-17245 Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating PDF report… Kibana after 6.4.2 Fix from $2,3002018-12-20 CRITICAL 9.8 CVE-2018-17246EPSS 82% Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console… Kibana 5.6.13 / 6.4.3+ Fix from $2,3002018-12-20 MEDIUM 6.5 CVE-2018-17244 Elasticsearch Security versions 6.4.0 to 6.4.2 contain an error in the way request headers are applied to requests when using the Active Directory, L… Elasticsearch after 6.4.2 Fix from $1,6002018-12-20 MEDIUM 5.9 CVE-2018-17247 Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a policy allowing external netw… Elasticsearch Mitigation only Fix from $1,6002018-12-20 HIGH 8.8 CVE-2018-3831 Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured via the API… Elasticsearch 5.6.12 / 6.4.1+ Fix from $1,9502018-09-19 MEDIUM 6.1 CVE-2018-3830 Kibana versions 5.3.0 to 6.4.1 had a cross-site scripting (XSS) vulnerability via the source field formatter that could allow an attacker to obtain s… Kibana after 6.4.1 Fix from $1,6002018-09-19 MEDIUM 5.3 CVE-2018-3829 In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invalid roles… Elastic Cloud Enterprise 1.1.4+ Fix from $1,6002018-09-19 HIGH 8.1 CVE-2018-3827 A sensitive data disclosure flaw was found in the Elasticsearch repository-azure (formerly elasticsearch-cloud-azure) plugin. When the repository-azu… Azure Repository after 6.2.4 Fix from $1,9502018-09-19 HIGH 7.5 CVE-2018-3828 Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exception condit… Elastic Cloud Enterprise 1.1.4+ Fix from $1,9502018-09-19 MEDIUM 6.5 CVE-2018-3826 In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameters are … Elasticsearch after 6.2.4 Fix from $1,6002018-09-19 MEDIUM 6.1 CVE-2018-3824 X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. If an attacker is able to inject data into an… Elasticsearch X Pack 5.6.9 / 6.2.4+ Fix from $1,6002018-09-19