Vulnerability index

Browse CVEs

221 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2016-10366 Kibana versions after and including 4.3 and before 4.6.2 are vulnerable to a cross-site scripting (XSS) attack. Kibana Mitigation only Fix from $1,6002017-06-16 MEDIUM 6.1 CVE-2017-8451 With X-Pack installed, Kibana versions before 5.3.1 have an open redirect vulnerability on the login page that would enable an attacker to craft a li… Kibana after 5.3.0 Fix from $1,6002017-06-16 MEDIUM 5.9 CVE-2017-8449 X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules used a mix of grant and excl… X Pack after 5.2.2 Fix from $1,6002017-06-16 HIGH 8.8 CVE-2017-8438 Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality. This bug prevents transitioning into … X Pack Patch available Fix from $1,9502017-06-05 MEDIUM 6.1 CVE-2017-8439 Kibana version 5.4.0 was affected by a Cross Site Scripting (XSS) bug in the Time Series Visual Builder. This bug could allow an attacker to obtain s… Kibana Mitigation only Fix from $1,6002017-06-05 MEDIUM 6.1 CVE-2017-8440 Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow an attacker to obtain sensitiv… Kibana Mitigation only Fix from $1,6002017-06-05 MEDIUM 6.8 CVE-2015-8131 Cross-site request forgery (CSRF) vulnerability in Elasticsearch Kibana before 4.1.3 and 4.2.x before 4.2.1 allows remote attackers to hijack the aut… Kibana after 4.1.2 Fix from $1,6002015-12-07 MEDIUM 6.4 CVE-2015-4152 Directory traversal vulnerability in the file output plugin in Elasticsearch Logstash before 1.4.3 allows remote attackers to write to arbitrary file… Logstash after 1.4.2 Fix from $1,6002015-06-15 CRITICAL 9.8 CVE-2015-1427 KEVEPSS 100% The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism a… Elasticsearch 1.3.8 / 1.4.3+ Fix from $2,3002015-02-17 HIGH 8.1 CVE-2014-3120 KEVEPSS 89% The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions … Elasticsearch 1.2.0+ Fix from $1,9502014-07-28 HIGH 7.5 CVE-2014-4326 Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows remote attackers to execute arbitrary commands via a crafted event in (1) zabbix.rb o… Logstash Mitigation only Fix from $1,9502014-07-22