Skip to content
Noroxi

Elastic records

349 published records for vendor elastic.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

349 records
  • The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection me

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    elastic · elasticsearchFeb 17, 2015

  • Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer.

    CriticalCVSS 10.0KEVWeaponizedEPSS 95%

    elastic · kibanaMar 25, 2019

  • The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL exp

    HighCVSS 8.1KEVWeaponizedEPSS 89%

    elastic · elasticsearchJul 28, 2014

  • CVE-2018-17246
    64This week

    Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin.

    CriticalCVSS 9.8Proof of conceptEPSS 82%

    elastic · kibanaDec 20, 2018

  • A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting.

    MediumCVSS 6.5WeaponizedEPSS 76%

    elastic · elasticsearchJul 21, 2021

  • Elasticsearch StackOverflow vulnerability

    HighCVSS 7.5Proof of conceptEPSS 62%

    elastic · elasticsearchOct 26, 2023

  • Kibana arbitrary code execution via prototype pollution

    CriticalCVSS 9.8Proof of conceptEPSS 21%

    elastic · kibanaMay 6, 2025

  • Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol.

    CriticalCVSS 9.8Proof of conceptEPSS 14%

    elastic · elasticsearchMar 6, 2018

  • All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters.

    HighCVSS 7.5Proof of conceptEPSS 36%

    elastic · elasticsearchJul 21, 2021

  • Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant.

    HighCVSS 8.8WeaponizedEPSS 18%

    elastic · kibanaJun 3, 2020

  • A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs.

    CriticalCVSS 9.8No exploitEPSS 2%

    elastic · logstashMar 25, 2019

  • CVE-2018-3822
    39Monitor

    X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM tr

    CriticalCVSS 9.8No exploitEPSS 2%

    elastic · x-packMar 30, 2018

  • Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating P

    CriticalCVSS 9.8No exploitEPSS 2%

    elastic · kibanaDec 20, 2018

  • Kibana arbitrary code execution via prototype pollution

    CriticalCVSS 9.9No exploitEPSS 1%

    elastic · kibanaMar 5, 2025

  • Improper Limitation of a Pathname to a Restricted Directory in Logstash Leading to Arbitrary File Write

    CriticalCVSS 9.8No exploitEPSS 1%

    elastic · logstashApr 8, 2026

  • It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subs

    CriticalCVSS 9.8No exploitEPSS 1%

    elastic · elastic cloud enterpriseJun 28, 2024

  • Kibana Prototype Pollution can lead to code injection

    CriticalCVSS 9.8No exploitEPSS 1%

    elastic · kibanaApr 8, 2025

  • CVE-2019-7610
    37Monitor

    Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger.

    CriticalCVSS 9.0No exploitEPSS 4%

    elastic · kibanaMar 25, 2019

  • CVE-2018-3831
    36Monitor

    Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured vi

    HighCVSS 8.8No exploitEPSS 2%

    elastic · elasticsearchSep 19, 2018

  • Improper Control of Generation of Code in Fleet Server Leading to Code Injection

    CriticalCVSS 9.1No exploitEPSS 1%

    elastic · kibanaAug 13, 2026

  • Elastic Endpoint Insertion of Sensitive Information into Log File

    CriticalCVSS 9.1No exploitEPSS 0%

    elastic · endpointOct 25, 2023

  • CVE-2020-7009
    35Monitor

    Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create A

    HighCVSS 8.8No exploitEPSS 2%

    elastic · elasticsearchMar 31, 2020

  • CVE-2020-7014
    35Monitor

    The fix for CVE-2020-7009 was found to be incomplete.

    HighCVSS 8.8No exploitEPSS 2%

    elastic · elasticsearchJun 3, 2020

  • CVE-2020-7018
    35Monitor

    Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface.

    HighCVSS 8.8No exploitEPSS 1%

    elastic · enterprise searchAug 18, 2020

  • CVE-2017-8438
    35Monitor

    Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality.

    HighCVSS 8.8No exploitEPSS 1%

    elastic · x-packJun 5, 2017