Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Flx HIGH 8.1
CVE-2026-4818

In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary privileges to execute some manage…

Fix: 4.1.0+
Fix from $1,950 2026-03-31
Flx MEDIUM 6.5
CVE-2026-4819

In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users logging into Kibana.

Fix: 4.1.0+
Fix from $1,600 2026-03-31
Search Guard HIGH 8.8
CVE-2019-13423

Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an authenticated Kibana user could impersonate as kibanaserv…

Fix: 5.6.8-7 / 6.2.3-12+
Fix from $1,950 2019-08-23
Search Guard MEDIUM 6.1
CVE-2019-13422

Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an attacker can redirect the user to a potentially malicious…

Fix: 5.6.8-7 / 6.2.3-12+
Fix from $1,600 2019-08-23
Search Guard MEDIUM 6.5
CVE-2019-13415

Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users can gain read access to data they are…

Fix: 24.3+
Fix from $1,600 2019-08-13
Search Guard MEDIUM 6.5
CVE-2019-13416

Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users are always authorized on the local cl…

Fix: 24.3+
Fix from $1,600 2019-08-13
Search Guard HIGH 7.5
CVE-2019-13419

Search Guard versions before 23.1 had an issue that for aggregations clear text values of anonymised fields were leaked.

Fix: 23.1+
Fix from $1,950 2019-08-13
Search Guard MEDIUM 5.9
CVE-2019-13420

Search Guard versions before 21.0 had an timing side channel issue when using the internal user database.

Fix: 21.0+
Fix from $1,600 2019-08-13
Search Guard HIGH 7.5
CVE-2019-13418

Search Guard versions before 24.0 had an issue that values of string arrays in documents are not properly anonymized.

Fix: 24.0+
Fix from $1,950 2019-08-12
Search Guard MEDIUM 5.3
CVE-2019-13417

Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for…

Fix: 24.0+
Fix from $1,600 2019-08-12
Search Guard MEDIUM 6.1
CVE-2018-20698

The floragunn Search Guard plugin before 6.x-16 for Kibana allows URL injection for login redirects on the login page when basePath is set.

Fix: 6.3.0-16+
Fix from $1,600 2019-04-09