Elastic

Elasticsearch

46 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Veröffentlicht 08.03.2021 21:15:16
  • Zuletzt bearbeitet 21.11.2024 05:49:34

A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query against a recently updated docu...

  • EPSS 0.29%
  • Veröffentlicht 10.02.2021 19:15:11
  • Zuletzt bearbeitet 21.11.2024 05:36:30

Elasticsearch versions before 7.10.0 and 6.8.14 have an information disclosure issue when audit logging and the emit_request_body option is enabled. The Elasticsearch audit log could contain sensitive information such as password hashes or authentica...

  • EPSS 0.41%
  • Veröffentlicht 14.01.2021 20:15:13
  • Zuletzt bearbeitet 21.11.2024 05:49:34

Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obt...

  • EPSS 0.08%
  • Veröffentlicht 22.10.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:36:30

Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain complex queries. This could result in...

  • EPSS 0.11%
  • Veröffentlicht 18.08.2020 17:15:11
  • Zuletzt bearbeitet 21.11.2024 05:36:30

In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security. If a user runs the same query another more privileged user recently ran, the scrolling search can leak fields that s...

  • EPSS 0.47%
  • Veröffentlicht 03.06.2020 18:15:23
  • Zuletzt bearbeitet 21.11.2024 05:36:29

The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication tokens. An attacker who is able ...

  • EPSS 2.12%
  • Veröffentlicht 31.03.2020 19:15:14
  • Zuletzt bearbeitet 21.11.2024 05:36:29

Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API ke...

  • EPSS 1.6%
  • Veröffentlicht 30.10.2019 14:15:11
  • Zuletzt bearbeitet 21.11.2024 04:48:24

Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker could send a specially crafted request and determine if a username exists in the Elasticsearch native ...

  • EPSS 0.25%
  • Veröffentlicht 30.07.2019 22:15:12
  • Zuletzt bearbeitet 21.11.2024 04:48:24

A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gain access to response header co...

  • EPSS 0.71%
  • Veröffentlicht 25.03.2019 19:29:02
  • Zuletzt bearbeitet 21.11.2024 04:48:23

A permission issue was found in Elasticsearch versions before 5.6.15 and 6.6.1 when Field Level Security and Document Level Security are disabled and the _aliases, _shrink, or _split endpoints are used . If the elasticsearch.yml file has xpack.securi...