<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Elasticsearch (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/elasticsearch.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/elasticsearch-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Elasticsearch (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:40 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-31215 – The nexent v1.7.5.2 backend service contains an unauthorized arbitrary file dele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31215</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31215</guid>
    <pubDate>Tue, 12 May 2026 16:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-31215</strong></p>
  <p>The nexent v1.7.5.2 backend service contains an unauthorized arbitrary file deletion vulnerability in its ElasticSearch service interface. The DELETE /{index_name}/documents endpoint lacks proper authentication and authorization controls and does not validate the user-supplied path_or_url parameter. This allows unauthenticated remote attackers to send crafted requests that trigger the deletion of…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-552</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31215">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4498 – Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4498</guid>
    <pubDate>Wed, 08 Apr 2026 17:21:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4498</strong></p>
  <p>Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index data beyond their direct Elasticsearch RBAC scope via Privilege Abuse (CAPEC-122). This requires an authenticated Kibana user with Fleet sub-feature privileges (such as agents, agent policies, and settings management).</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-12977 – Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to saniti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12977</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12977</guid>
    <pubDate>Mon, 24 Nov 2025 15:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-12977</strong></p>
  <p>Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to sanitize tag_key inputs. An attacker with network access or the ability to write records into Splunk or Elasticsearch can supply tag_key values containing special characters such as newlines or ../ that are treated as valid tags. Because tags influence routing and some outputs derive filenames or contents from tags, this ca…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-1287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12977">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-44824 – Nagios Log Server before 2024R1.3.2 allows authenticated users (with read-only A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-44824</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-44824</guid>
    <pubDate>Tue, 07 Oct 2025 20:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-44824</strong></p>
  <p>Nagios Log Server before 2024R1.3.2 allows authenticated users (with read-only API access) to stop the Elasticsearch service via a /nagioslogserver/index.php/api/system/stop?subsystem=elasticsearch call. The service stops even though "message": "Could not stop elasticsearch" is in the API response. This is GL:NLS#474.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-44824">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-57564 – CubeAPM nightly-2025-08-01-1 allow unauthenticated attackers to inject arbitrary...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57564</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57564</guid>
    <pubDate>Tue, 07 Oct 2025 14:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-57564</strong></p>
  <p>CubeAPM nightly-2025-08-01-1 allow unauthenticated attackers to inject arbitrary log entries into production systems via the /api/logs/insert/elasticsearch/_bulk endpoint. This endpoint accepts bulk log data without requiring authentication or input validation, allowing remote attackers to perform unauthorized log injection. Exploitation may lead to false log entries, log poisoning, alert obfusca…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-117</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57564">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-37285 – A deserialization issue in Kibana can lead to arbitrary code execution when Kiba...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37285</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37285</guid>
    <pubDate>Thu, 14 Nov 2024 17:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-37285</strong></p>
  <p>A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. A successful attack requires a malicious user to have a combination of both specific  Elasticsearch indices privileges https://www.elastic.co/guide/en/elasticsearch/reference/current/defining-roles.html#roles-indices-priv  and  Kibana privileges https:…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37285">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46675 – An issue was discovered by Elastic whereby sensitive information may be recorded...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46675</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46675</guid>
    <pubDate>Wed, 13 Dec 2023 07:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46675</strong></p>
  <p>An issue was discovered by Elastic whereby sensitive information may be recorded in Kibana logs in the event of an error or in the event where debug level logging is enabled in Kibana. Elastic has released Kibana 8.11.2 which resolves this issue. The messages recorded in the log may contain Account credentials for the kibana_system user, API Keys, and credentials of Kibana end-users, Elastic Secu…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46675">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46671 – An issue was discovered by Elastic whereby sensitive information may be recorded...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46671</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46671</guid>
    <pubDate>Wed, 13 Dec 2023 07:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46671</strong></p>
  <p>An issue was discovered by Elastic whereby sensitive information may be recorded in Kibana logs in the event of an error. Elastic has released Kibana 8.11.1 which resolves this issue. The error message recorded in the log may contain account credentials for the kibana_system user, API Keys, and credentials of Kibana end-users. The issue occurs infrequently, only if an error is returned from an El…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46671">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-31418 – An issue has been identified with how Elasticsearch handled incoming requests on...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-31418</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-31418</guid>
    <pubDate>Thu, 26 Oct 2023 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-31418</strong></p>
  <p>An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. The issue was identified by Elastic Engineering and we have no indication that the issue is known or that it is being exploited in the wild.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-31418">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46667 – An issue was discovered in Fleet Server &gt;= v8.10.0 and &lt; v8.10.3 where Agent enr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46667</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46667</guid>
    <pubDate>Thu, 26 Oct 2023 01:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46667</strong></p>
  <p>An issue was discovered in Fleet Server >= v8.10.0 and < v8.10.3 where Agent enrolment tokens are being inserted into the Fleet Server’s log file in plain text. These enrolment tokens could allow someone to enrol an agent into an agent policy, and potentially use that to retrieve other secrets in the policy including for Elasticsearch and third-party services. Alternatively a threat actor could p…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46667">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20034 – Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20034</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20034</guid>
    <pubDate>Wed, 27 Sep 2023 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20034</strong></p>
  <p>Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to access the Elasticsearch configuration database of an affected device with the privileges of the elasticsearch user.  These vulnerability is due to the presence of a static username and password configured on the vManage. An attacker could exploit this vuln…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20034">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-38656 – HCL Commerce, when using Elasticsearch, can allow a remote attacker to cause a d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-38656</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-38656</guid>
    <pubDate>Mon, 12 Dec 2022 13:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-38656</strong></p>
  <p>HCL Commerce, when using Elasticsearch, can allow a remote attacker to cause a denial of service attack on the site and make administrative changes.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38656">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-42123 – A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42123</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42123</guid>
    <pubDate>Tue, 15 Nov 2022 01:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-42123</strong></p>
  <p>A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before update 19 allows attackers to create or overwrite existing files on the filesystem via the installation of a malicious Elasticsearch Sidecar plugin.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42123">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31115 – opensearch-ruby is a community-driven, open source fork of elasticsearch-ruby. I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31115</guid>
    <pubDate>Thu, 30 Jun 2022 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31115</strong></p>
  <p>opensearch-ruby is a community-driven, open source fork of elasticsearch-ruby. In versions prior to 2.0.1 the ruby `YAML.load` function was used instead of `YAML.safe_load`. As a result opensearch-ruby 2.0.0 and prior can lead to unsafe deserialization using YAML.load if the response is of type YAML. An attacker must be in control of an opensearch server and convince the victim to connect to it i…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-23712 – A Denial of Service flaw was discovered in Elasticsearch. Using this vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23712</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23712</guid>
    <pubDate>Mon, 06 Jun 2022 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-23712</strong></p>
  <p>A Denial of Service flaw was discovered in Elasticsearch. Using this vulnerability, an unauthenticated attacker could forcibly shut down an Elasticsearch node with a specifically formatted network request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23712">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22146 – All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22146</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22146</guid>
    <pubDate>Wed, 21 Jul 2021 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22146</strong></p>
  <p>All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the default setting the anonymous user has no permissions and is unable to successfully query any Elasticsearch APIs, an attacker could leverage the anonymous user to gain insight into certain details of a deployed cluster.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22146">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32743 – Icinga is a monitoring system which checks the availability of network resources...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32743</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32743</guid>
    <pubDate>Thu, 15 Jul 2021 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32743</strong></p>
  <p>Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions prior to 2.11.10 and from version 2.12.0 through version 2.12.4, some of the Icinga 2 features that require credentials for external services expose those credentials through the API to authenticated API users with read permissions…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-202</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32743">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-31828 – An SSRF issue in Open Distro for Elasticsearch (ODFE) before 1.13.1.0 allows an ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-31828</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-31828</guid>
    <pubDate>Thu, 06 May 2021 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-31828</strong></p>
  <p>An SSRF issue in Open Distro for Elasticsearch (ODFE) before 1.13.1.0 allows an existing privileged user to enumerate listening services or interact with configured resources via HTTP requests exceeding the Alerting plugin's intended scope.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31828">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22997 – On all 7.x and 6.x versions (fixed in 8.0.0), BIG-IQ HA ElasticSearch service do...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22997</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22997</guid>
    <pubDate>Wed, 31 Mar 2021 18:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22997</strong></p>
  <p>On all 7.x and 6.x versions (fixed in 8.0.0), BIG-IQ HA ElasticSearch service does not implement any form of authentication for the clustering transport services, and all data used by ElasticSearch for transport is unencrypted. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22997">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-15097 – loklak is an open-source server application which is able to collect messages fr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15097</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15097</guid>
    <pubDate>Tue, 02 Feb 2021 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-15097</strong></p>
  <p>loklak is an open-source server application which is able to collect messages from various sources, including twitter. The server contains a search index and a peer-to-peer index sharing interface. All messages are stored in an elasticsearch index. In loklak less than or equal to commit 5f48476, a path traversal vulnerability exists. Insufficient input validation in the APIs exposed by the loklak…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15097">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7014 – The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions fro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7014</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7014</guid>
    <pubDate>Wed, 03 Jun 2020 18:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7014</strong></p>
  <p>The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication tokens. An attacker who is able to generate an API key and an authentication token can perform a series of steps that result in an authentication token being generated with elevated…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7014">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7010 – Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords usi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7010</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7010</guid>
    <pubDate>Wed, 03 Jun 2020 18:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7010</strong></p>
  <p>Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator. If an attacker is able to determine when the current Elastic Stack cluster was deployed they may be able to more easily brute force the Elasticsearch credentials generated by ECK.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-335</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7010">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7009 – Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7009</guid>
    <pubDate>Tue, 31 Mar 2020 19:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7009</strong></p>
  <p>Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API key being generated with elevated privileges.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7009">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15590 – An access control issue exists in &lt; 12.3.5, &lt; 12.2.8, and &lt; 12.1.14 for GitLab C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15590</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15590</guid>
    <pubDate>Tue, 28 Jan 2020 03:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15590</strong></p>
  <p>An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elasticsearch integration</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15590">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19629 – In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19629</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19629</guid>
    <pubDate>Sun, 05 Jan 2020 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19629</strong></p>
  <p>In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private code would be disclosed via the Group Search API provided by the Elasticsearch integration.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19629">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-18460 – An issue was discovered in GitLab Community and Enterprise Edition 8.15 through ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18460</guid>
    <pubDate>Tue, 26 Nov 2019 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-18460</strong></p>
  <p>An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4 in the Comments Search feature provided by the Elasticsearch integration. It has Incorrect Access Control.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-7611 – A permission issue was found in Elasticsearch versions before 5.6.15 and 6.6.1 w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-7611</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-7611</guid>
    <pubDate>Mon, 25 Mar 2019 19:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-7611</strong></p>
  <p>A permission issue was found in Elasticsearch versions before 5.6.15 and 6.6.1 when Field Level Security and Document Level Security are disabled and the _aliases, _shrink, or _split endpoints are used . If the elasticsearch.yml file has xpack.security.dls_fls.enabled set to false, certain permission checks are skipped when users perform one of the actions mentioned above, to make existing data a…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-7611">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-3831 – Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-3831</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-3831</guid>
    <pubDate>Wed, 19 Sep 2018 19:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-3831</strong></p>
  <p>Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured via the API. The Elasticsearch _cluster/settings API, when queried, could leak sensitive configuration information such as passwords, tokens, or usernames. This could allow an authenticated Elasticsearch user to improperly view these details.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-3831">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-3827 – A sensitive data disclosure flaw was found in the Elasticsearch repository-azure...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-3827</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-3827</guid>
    <pubDate>Wed, 19 Sep 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-3827</strong></p>
  <p>A sensitive data disclosure flaw was found in the Elasticsearch repository-azure (formerly elasticsearch-cloud-azure) plugin. When the repository-azure plugin is set to log at TRACE level Azure credentials can be inadvertently logged.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-3827">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-8074 – Yii 2.x before 2.0.15 allows remote attackers to inject unintended search condit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-8074</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-8074</guid>
    <pubDate>Wed, 21 Mar 2018 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-8074</strong></p>
  <p>Yii 2.x before 2.0.15 allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269 attack in conjunction with the Elasticsearch extension.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-8074">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-5377 – Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-5377</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-5377</guid>
    <pubDate>Tue, 06 Mar 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-5377</strong></p>
  <p>Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol.  NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerability</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5377">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-12629 – Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-12629</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-12629</guid>
    <pubDate>Sat, 14 Oct 2017 23:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-12629</strong></p>
  <p>Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch, although it uses Lucene, is NOT vulnerable to this. Note that the XML external entity expansion vulnerability occurs in the XML Query Parser which is available, by default, for a…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-12629">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-4165 – The snapshot API in Elasticsearch before 1.6.0 when another application exists o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-4165</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-4165</guid>
    <pubDate>Wed, 09 Aug 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-4165</strong></p>
  <p>The snapshot API in Elasticsearch before 1.6.0 when another application exists on the system that can read Lucene files and execute code from them, is accessible by the attacker, and the Java VM on which Elasticsearch is running can write to a location that the other application can read and execute from, allows remote authenticated users to write to and create arbitrary snapshot metadata files,…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-4165">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-1000221 – Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file H...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-1000221</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-1000221</guid>
    <pubDate>Fri, 16 Jun 2017 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-1000221</strong></p>
  <p>Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could contain sensitive information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-1000221">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-1427 – The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-1427</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-1427</guid>
    <pubDate>Tue, 17 Feb 2015 15:59:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-1427</strong></p>
  <p>The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-1427">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-3120 – The default configuration in Elasticsearch before 1.2 enables dynamic scripting,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-3120</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-3120</guid>
    <pubDate>Mon, 28 Jul 2014 19:55:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-3120</strong></p>
  <p>The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search.  NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-3120">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-4326 – Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows remote attackers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-4326</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-4326</guid>
    <pubDate>Tue, 22 Jul 2014 14:55:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-4326</strong></p>
  <p>Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows remote attackers to execute arbitrary commands via a crafted event in (1) zabbix.rb or (2) nagios_nsca.rb in outputs/.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-4326">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
