Записи Elastic
349 опубликованных записей вендора elastic.
Профиль для исследователя
- Попали в KEV
- 3 · 0,9 %
- С эксплойтом
- 5 · 1,4 %
- Pre-auth RCE
- 11
- С записью об исправлении
- 30,1 %
- Медиана: публикация → KEV
- 2593 дн.
Повторяющиеся классы
- CWE-400 Uncontrolled Resource Consumption30
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')28
- CWE-863 Incorrect Authorization26
- CWE-770 Allocation of Resources Without Limits or Throttling26
- CWE-532 Insertion of Sensitive Information into Log File23
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor17
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
349 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2015-1427Готовый эксплойт | The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection meelastic · elasticsearch | Критическая9,8 | KEV | 99,9 % | 17 февр. 2015 г. |
99Срочно | CVE-2019-7609Готовый эксплойт | Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer.elastic · kibana · CWE-94 | Критическая10,0 | KEV | 95,3 % | 25 мар. 2019 г. |
89Срочно | CVE-2014-3120Готовый эксплойт | The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expelastic · elasticsearch · CWE-284 | Высокая8,1 | KEV | 88,6 % | 28 июл. 2014 г. |
64На этой неделе | CVE-2018-17246Proof of concept | Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin.elastic · kibana · CWE-73 | Критическая9,8 | — | 82,3 % | 20 дек. 2018 г. |
49В плане | CVE-2021-22145Готовый эксплойт | A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting.elastic · elasticsearch · CWE-200 | Средняя6,5 | — | 76,2 % | 21 июл. 2021 г. |
49В плане | CVE-2023-31419Proof of concept | Elasticsearch StackOverflow vulnerabilityelastic · elasticsearch · CWE-121 | Высокая7,5 | — | 61,7 % | 26 окт. 2023 г. |
45В плане | CVE-2025-25014Proof of concept | Kibana arbitrary code execution via prototype pollutionelastic · kibana · CWE-1321 | Критическая9,8 | — | 21,5 % | 6 мая 2025 г. |
43В плане | CVE-2015-5377Proof of concept | Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol.elastic · elasticsearch · CWE-74 | Критическая9,8 | — | 14,3 % | 6 мар. 2018 г. |
41В плане | CVE-2021-22146Proof of concept | All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters.elastic · elasticsearch | Высокая7,5 | — | 35,8 % | 21 июл. 2021 г. |
40В плане | CVE-2020-7012Готовый эксплойт | Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant.elastic · kibana · CWE-94 | Высокая8,8 | — | 18,2 % | 3 июн. 2020 г. |
40В плане | CVE-2019-7612Эксплойта нет | A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs.elastic · logstash · CWE-209 | Критическая9,8 | — | 2,4 % | 25 мар. 2019 г. |
39Наблюдать | CVE-2018-3822Эксплойта нет | X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM trelastic · x-pack · CWE-287 | Критическая9,8 | — | 1,6 % | 30 мар. 2018 г. |
39Наблюдать | CVE-2018-17245Эксплойта нет | Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating Pelastic · kibana · CWE-201 | Критическая9,8 | — | 1,5 % | 20 дек. 2018 г. |
39Наблюдать | CVE-2025-25015Эксплойта нет | Kibana arbitrary code execution via prototype pollutionelastic · kibana · CWE-1321 | Критическая9,9 | — | 1,3 % | 5 мар. 2025 г. |
39Наблюдать | CVE-2026-33466Эксплойта нет | Improper Limitation of a Pathname to a Restricted Directory in Logstash Leading to Arbitrary File Writeelastic · logstash · CWE-22 | Критическая9,8 | — | 0,8 % | 8 апр. 2026 г. |
39Наблюдать | CVE-2024-37282Эксплойта нет | It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subselastic · elastic cloud enterprise · CWE-285 | Критическая9,8 | — | 0,6 % | 28 июн. 2024 г. |
39Наблюдать | CVE-2024-12556Эксплойта нет | Kibana Prototype Pollution can lead to code injectionelastic · kibana · CWE-1321 | Критическая9,8 | — | 0,5 % | 8 апр. 2025 г. |
37Наблюдать | CVE-2019-7610Эксплойта нет | Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger.elastic · kibana · CWE-94 | Критическая9,0 | — | 3,9 % | 25 мар. 2019 г. |
36Наблюдать | CVE-2018-3831Эксплойта нет | Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured vielastic · elasticsearch · CWE-200 | Высокая8,8 | — | 2,0 % | 19 сент. 2018 г. |
36Наблюдать | CVE-2026-72676Эксплойта нет | Improper Control of Generation of Code in Fleet Server Leading to Code Injectionelastic · kibana · CWE-94 | Критическая9,1 | — | 0,5 % | 13 авг. 2026 г. |
36Наблюдать | CVE-2023-46668Эксплойта нет | Elastic Endpoint Insertion of Sensitive Information into Log Fileelastic · endpoint · CWE-532 | Критическая9,1 | — | 0,3 % | 25 окт. 2023 г. |
35Наблюдать | CVE-2020-7009Эксплойта нет | Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create Aelastic · elasticsearch · CWE-266 | Высокая8,8 | — | 1,6 % | 31 мар. 2020 г. |
35Наблюдать | CVE-2020-7014Эксплойта нет | The fix for CVE-2020-7009 was found to be incomplete.elastic · elasticsearch · CWE-266 | Высокая8,8 | — | 1,5 % | 3 июн. 2020 г. |
35Наблюдать | CVE-2020-7018Эксплойта нет | Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface.elastic · enterprise search · CWE-266 | Высокая8,8 | — | 1,1 % | 18 авг. 2020 г. |
35Наблюдать | CVE-2017-8438Эксплойта нет | Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality.elastic · x-pack · CWE-284 | Высокая8,8 | — | 1,0 % | 5 июн. 2017 г. |
- CVE-2015-142799Срочно
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection me
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %elastic · elasticsearch17 февр. 2015 г.
- CVE-2019-760999Срочно
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer.
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 95 %elastic · kibana25 мар. 2019 г.
- CVE-2014-312089Срочно
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL exp
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 89 %elastic · elasticsearch28 июл. 2014 г.
- CVE-2018-1724664На этой неделе
Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin.
КритическаяCVSS 9,8Proof of conceptEPSS 82 %elastic · kibana20 дек. 2018 г.
- CVE-2021-2214549В плане
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting.
СредняяCVSS 6,5Готовый эксплойтEPSS 76 %elastic · elasticsearch21 июл. 2021 г.
- CVE-2023-3141949В плане
Elasticsearch StackOverflow vulnerability
ВысокаяCVSS 7,5Proof of conceptEPSS 62 %elastic · elasticsearch26 окт. 2023 г.
- CVE-2025-2501445В плане
Kibana arbitrary code execution via prototype pollution
КритическаяCVSS 9,8Proof of conceptEPSS 21 %elastic · kibana6 мая 2025 г.
- CVE-2015-537743В плане
Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol.
КритическаяCVSS 9,8Proof of conceptEPSS 14 %elastic · elasticsearch6 мар. 2018 г.
- CVE-2021-2214641В плане
All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters.
ВысокаяCVSS 7,5Proof of conceptEPSS 36 %elastic · elasticsearch21 июл. 2021 г.
- CVE-2020-701240В плане
Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant.
ВысокаяCVSS 8,8Готовый эксплойтEPSS 18 %elastic · kibana3 июн. 2020 г.
- CVE-2019-761240В плане
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %elastic · logstash25 мар. 2019 г.
- CVE-2018-382239Наблюдать
X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM tr
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %elastic · x-pack30 мар. 2018 г.
- CVE-2018-1724539Наблюдать
Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating P
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %elastic · kibana20 дек. 2018 г.
- CVE-2025-2501539Наблюдать
Kibana arbitrary code execution via prototype pollution
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %elastic · kibana5 мар. 2025 г.
- CVE-2026-3346639Наблюдать
Improper Limitation of a Pathname to a Restricted Directory in Logstash Leading to Arbitrary File Write
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %elastic · logstash8 апр. 2026 г.
- CVE-2024-3728239Наблюдать
It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subs
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %elastic · elastic cloud enterprise28 июн. 2024 г.
- CVE-2024-1255639Наблюдать
Kibana Prototype Pollution can lead to code injection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %elastic · kibana8 апр. 2025 г.
- CVE-2019-761037Наблюдать
Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger.
КритическаяCVSS 9,0Эксплойта нетEPSS 4 %elastic · kibana25 мар. 2019 г.
- CVE-2018-383136Наблюдать
Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured vi
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %elastic · elasticsearch19 сент. 2018 г.
- CVE-2026-7267636Наблюдать
Improper Control of Generation of Code in Fleet Server Leading to Code Injection
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %elastic · kibana13 авг. 2026 г.
- CVE-2023-4666836Наблюдать
Elastic Endpoint Insertion of Sensitive Information into Log File
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %elastic · endpoint25 окт. 2023 г.
- CVE-2020-700935Наблюдать
Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create A
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %elastic · elasticsearch31 мар. 2020 г.
- CVE-2020-701435Наблюдать
The fix for CVE-2020-7009 was found to be incomplete.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %elastic · elasticsearch3 июн. 2020 г.
- CVE-2020-701835Наблюдать
Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %elastic · enterprise search18 авг. 2020 г.
- CVE-2017-843835Наблюдать
Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %elastic · x-pack5 июн. 2017 г.