Elastic

Elastic Agent

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 01.05.2025 13:03:58
  • Zuletzt bearbeitet 01.10.2025 19:28:58

Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd, allows local attackers to execute arbitrary code via parameter injection. An attacker requires local access and the ability to modify osqueryd configu...

  • EPSS 0.01%
  • Veröffentlicht 01.05.2025 12:59:49
  • Zuletzt bearbeitet 01.10.2025 19:31:08

Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead to loss of confidentiality and impersonation of Endpoint to the Elastic Stack. This issue was identified by Elastic engineers and E...

  • EPSS 0.27%
  • Veröffentlicht 12.08.2024 13:38:23
  • Zuletzt bearbeitet 29.09.2025 14:06:40

An issue was discovered whereby Elastic Agent will leak secrets from the agent policy elastic-agent.yml only when the log level is configured to debug. By default the log level is set to info, where no leak occurs.

  • EPSS 0.4%
  • Veröffentlicht 12.12.2023 19:15:08
  • Zuletzt bearbeitet 21.11.2024 08:44:20

An issue was discovered by Elastic whereby Elastic Agent would log a raw event in its own logs at the WARN or ERROR level if ingesting that event to Elasticsearch failed with any 4xx HTTP status code except 409 or 429. Depending on the nature of the ...

  • EPSS 0.09%
  • Veröffentlicht 26.10.2023 04:15:16
  • Zuletzt bearbeitet 21.11.2024 08:01:49

It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whether the server certificate is valid for the target IP address; however, certificate signature validation is still performed. More...