VYPR

Vendor CVEs

Elastic

All CVEs

330 total · sorted by risk
  • CVE-2024-23445MedJun 12, 2024
    risk 0.42cvss 6.5epss 0.00

    It was identified that if a cross-cluster API key https://www.elastic.co/guide/en/elasticsearch/reference/8.14/security-api-create-cross-cluster-api-key.html#security-api-create-cross-cluster-api-key-request-body  restricts search for a given index using the query or the…

  • CVE-2024-23446MedFeb 7, 2024
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DLS) or Field-level security (FLS) when querying the .alerts-security.alerts-{space_id} indices. Users who are authorized to call this API may obtain…

  • CVE-2023-46673MedNov 22, 2023
    risk 0.42cvss 6.5epss 0.01

    It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.

  • CVE-2022-38778MedFeb 8, 2023
    risk 0.42cvss 6.5epss 0.01

    A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a request that crashes the Kibana server process.

  • CVE-2022-23715MedAug 25, 2022
    risk 0.42cvss 6.5epss 0.01

    A flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwords and Elasticsearch keystore settings values in logs such as the audit log or deployment logs in the Logging and Monitoring cluster. The affected APIs are…

  • CVE-2021-22147MedSep 15, 2021
    risk 0.42cvss 6.5epss 0.01

    Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.

  • CVE-2021-22144MedJul 26, 2021
    risk 0.42cvss 6.5epss 0.02

    In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit arbitrary queries to Elasticsearch could create a malicious…

  • CVE-2021-22139MedMay 13, 2021
    risk 0.42cvss 6.5epss 0.01

    Kibana versions before 7.12.1 contain a denial of service vulnerability was found in the webhook actions due to a lack of timeout or a limit on the request size. An attacker with permissions to create webhook actions could drain the Kibana host connection pool, making Kibana…

  • CVE-2020-7019MedAug 18, 2020
    risk 0.42cvss 6.5epss 0.01

    In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security. If a user runs the same query another more privileged user recently ran, the scrolling search can leak fields that should be hidden. This could…

  • CVE-2019-7620HigOct 30, 2019
    risk 0.42cvss 7.5epss 0.02

    Logstash versions before 7.4.1 and 6.8.4 contain a denial of service flaw in the Logstash Beats input plugin. An unauthenticated user who is able to connect to the port the Logstash beats input could send a specially crafted network packet that would cause Logstash to stop…

  • CVE-2019-7618MedOct 1, 2019
    risk 0.42cvss 6.5epss 0.01

    A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is possible to read arbitrary files from the local filesystem of the Kibana instance running Code with the permission of the Kibana…

  • CVE-2018-17244MedDec 20, 2018
    risk 0.42cvss 6.5epss 0.01

    Elasticsearch Security versions 6.4.0 to 6.4.2 contain an error in the way request headers are applied to requests when using the Active Directory, LDAP, Native, or File realms. A request may receive headers intended for another request if the same username is being…

  • CVE-2018-3826MedSep 19, 2018
    risk 0.42cvss 6.5epss 0.01

    In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameters are set using the _snapshot API they can be exposed as plain text by users able to query the _snapshot API.

  • CVE-2018-3817MedMar 30, 2018
    risk 0.42cvss 6.5epss 0.01

    When logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log sensitive information.

  • CVE-2017-11480HigDec 8, 2017
    risk 0.42cvss 7.5epss 0.01

    Packetbeat versions prior to 5.6.4 are affected by a denial of service flaw in the PostgreSQL protocol handler. If Packetbeat is listening for PostgreSQL traffic and a user is able to send arbitrary network traffic to the monitored port, the attacker could prevent Packetbeat…

  • CVE-2017-8447MedSep 29, 2017
    risk 0.42cvss 6.5epss 0.01

    An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index' permissions on an index in a cluster, they may be able to issue both delete and index requests against that index.

  • CVE-2017-8442MedJul 7, 2017
    risk 0.42cvss 6.5epss 0.01

    Elasticsearch X-Pack Security versions 5.0.0 to 5.4.3, when enabled, can result in the Elasticsearch _nodes API leaking sensitive configuration information, such as the paths and passphrases of SSL keys that were configured as part of an authentication realm. This could allow an…

  • CVE-2017-8443MedJun 30, 2017
    risk 0.42cvss 6.5epss 0.01

    In Kibana X-Pack security versions prior to 5.4.3 if a Kibana user opens a crafted Kibana URL the result could be a redirect to an improperly initialized Kibana login screen. If the user enters credentials on this screen, the credentials will appear in the URL bar. The…

  • CVE-2016-10364MedJun 16, 2017
    risk 0.42cvss 6.5epss 0.01

    With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any authenticated user could make requests to those services regardless of their own permissions.

  • CVE-2016-10362MedJun 16, 2017
    risk 0.42cvss 6.5epss 0.01

    Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file HTTP basic auth credentials.

  • CVE-2016-1000221HigJun 16, 2017
    risk 0.42cvss 7.5epss 0.02

    Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could contain sensitive information.

  • CVE-2026-63141MedJul 21, 2026
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without the required feature privileges, via direct requests to insufficiently protected product endpoints.

  • CVE-2019-7615HigJul 30, 2019
    risk 0.41cvss 7.4epss 0.01

    A TLS certificate validation flaw was found in Elastic APM agent for Ruby versions before 2.9.0. When specifying a trusted server CA certificate via the 'server_ca_cert' setting, the Ruby agent would not properly verify the certificate returned by the APM server. This could…

  • CVE-2025-68387MedDec 18, 2025
    risk 0.40cvss 6.1epss 0.00

    Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an unauthenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via a vulnerability a function…

  • CVE-2024-23442MedJun 14, 2024
    risk 0.40cvss 6.1epss 0.00

    An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.

  • CVE-2022-38779MedFeb 22, 2023
    risk 0.40cvss 6.1epss 0.01

    An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.

  • CVE-2021-22141MedNov 18, 2022
    risk 0.40cvss 6.1epss 0.01

    An open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously crafted URL, it could result in Kibana redirecting the user to an arbitrary website.

  • CVE-2022-23713MedJul 6, 2022
    risk 0.40cvss 6.1epss 0.01

    A cross-site-scripting (XSS) vulnerability was discovered in the Vega Charts Kibana integration which could allow arbitrary JavaScript to be executed in a victim’s browser.

  • CVE-2022-23710MedMar 3, 2022
    risk 0.40cvss 6.1epss 0.01

    A cross-site-scripting (XSS) vulnerability was discovered in the Data Preview Pane (previously known as Index Pattern Preview Pane) which could allow arbitrary JavaScript to be executed in a victim’s browser.

  • CVE-2020-27816MedDec 2, 2020
    risk 0.40cvss 6.1epss 0.01

    The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it is possible to replace the original openshift-logging console link (kibana console) to different one, created based on the new CR for the new kibana resource.…

  • CVE-2020-7011MedJun 3, 2020
    risk 0.40cvss 6.1epss 0.01

    Elastic App Search versions before 7.7.0 contain a cross site scripting (XSS) flaw when displaying document URLs in the Reference UI. If the Reference UI injects a URL into a result, that URL will be rendered by the web browser. If an attacker is able to control the contents of…

  • CVE-2019-7617HigAug 22, 2019
    risk 0.40cvss 7.2epss 0.02

    When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw if a remote attacker can control the proxy header. This could result in an attacker redirecting collected APM data to a proxy of their choosing.

  • CVE-2018-3830MedSep 19, 2018
    risk 0.40cvss 6.1epss 0.02

    Kibana versions 5.3.0 to 6.4.1 had a cross-site scripting (XSS) vulnerability via the source field formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

  • CVE-2018-3824MedSep 19, 2018
    risk 0.40cvss 6.1epss 0.01

    X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. If an attacker is able to inject data into an index that has a ML job running against it, then when another user views the results of the ML job it could allow the attacker to…

  • CVE-2018-3821MedMar 30, 2018
    risk 0.40cvss 6.1epss 0.01

    Kibana versions after 5.1.1 and before 5.6.7 and 6.1.3 had a cross-site scripting (XSS) vulnerability in the tag cloud visualization that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

  • CVE-2018-3820MedMar 30, 2018
    risk 0.40cvss 6.1epss 0.01

    Kibana versions after 6.1.0 and before 6.1.3 had a cross-site scripting (XSS) vulnerability in labs visualizations that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

  • CVE-2018-3819MedMar 30, 2018
    risk 0.40cvss 6.1epss 0.01

    The fix in Kibana for ESA-2017-23 was incomplete. With X-Pack security enabled, Kibana versions before 6.1.3 and 5.6.7 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.

  • CVE-2018-3818MedMar 30, 2018
    risk 0.40cvss 6.1epss 0.01

    Kibana versions 5.1.1 to 6.1.2 and 5.6.6 had a cross-site scripting (XSS) vulnerability via the colored fields formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

  • CVE-2017-11482MedDec 8, 2017
    risk 0.40cvss 6.1epss 0.01

    The Kibana fix for CVE-2017-8451 was found to be incomplete. With X-Pack installed, Kibana versions before 6.0.1 and 5.6.5 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.

  • CVE-2017-11481MedDec 8, 2017
    risk 0.40cvss 6.1epss 0.01

    Kibana versions prior to 6.0.1 and 5.6.5 had a cross-site scripting (XSS) vulnerability via URL fields that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

  • CVE-2017-11479MedSep 29, 2017
    risk 0.40cvss 6.1epss 0.01

    Kibana versions prior to 5.6.1 had a cross-site scripting (XSS) vulnerability in Timelion that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

  • CVE-2017-8451MedJun 16, 2017
    risk 0.40cvss 6.1epss 0.01

    With X-Pack installed, Kibana versions before 5.3.1 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.

  • CVE-2016-10366MedJun 16, 2017
    risk 0.40cvss 6.1epss 0.01

    Kibana versions after and including 4.3 and before 4.6.2 are vulnerable to a cross-site scripting (XSS) attack.

  • CVE-2016-10365MedJun 16, 2017
    risk 0.40cvss 6.1epss 0.01

    Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link in the Kibana domain that redirects to an arbitrary website.

  • CVE-2016-1000220MedJun 16, 2017
    risk 0.40cvss 6.1epss 0.01

    Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScript in users' browsers.

  • CVE-2015-9056MedJun 16, 2017
    risk 0.40cvss 6.1epss 0.01

    Kibana versions prior to 4.1.3 and 4.2.1 are vulnerable to a XSS attack.

  • CVE-2017-8440MedJun 5, 2017
    risk 0.40cvss 6.1epss 0.01

    Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

  • CVE-2017-8439MedJun 5, 2017
    risk 0.40cvss 6.1epss 0.01

    Kibana version 5.4.0 was affected by a Cross Site Scripting (XSS) bug in the Time Series Visual Builder. This bug could allow an attacker to obtain sensitive information from Kibana users.

  • CVE-2023-46674MedDec 5, 2023
    risk 0.39cvss 6.0epss 0.00

    An issue was identified that allowed the unsafe deserialization of java objects from hadoop or spark configuration properties that could have been modified by authenticated users. Elastic would like to thank Yakov Shafranovich, with Amazon Web Services for reporting this issue.

  • CVE-2021-37937MedNov 22, 2023
    risk 0.38cvss 5.9epss 0.01

    An issue was found with how API keys are created with the Fleet-Server service account. When an API key is created with a service account, it is possible that the API key could be created with higher privileges than intended. Using this vulnerability, a compromised Fleet-Server…

Page 4 of 7