VYPR

ECE

by Elastic

CVEs (2)

  • CVE-2025-37729CriOct 13, 2025
    risk 0.59cvss 9.1epss 0.01

    Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin access exfiltrating sensitive information and issuing commands via a specially crafted string where Jinjava variables are evaluated.

  • CVE-2022-23716MedSep 28, 2022
    risk 0.34cvss 5.3epss 0.01

    A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in deployment logs in the Logging and Monitoring cluster.