Elastic

Elasticsearch

42 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.14%
  • Veröffentlicht 18.08.2020 17:15:11
  • Zuletzt bearbeitet 21.11.2024 05:36:30

In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security. If a user runs the same query another more privileged user recently ran, the scrolling search can leak fields that s...

  • EPSS 0.57%
  • Veröffentlicht 03.06.2020 18:15:23
  • Zuletzt bearbeitet 21.11.2024 05:36:29

The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication tokens. An attacker who is able ...

  • EPSS 1.54%
  • Veröffentlicht 31.03.2020 19:15:14
  • Zuletzt bearbeitet 21.11.2024 05:36:29

Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API ke...

  • EPSS 2.16%
  • Veröffentlicht 30.10.2019 14:15:11
  • Zuletzt bearbeitet 21.11.2024 04:48:24

Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker could send a specially crafted request and determine if a username exists in the Elasticsearch native ...

  • EPSS 0.25%
  • Veröffentlicht 30.07.2019 22:15:12
  • Zuletzt bearbeitet 21.11.2024 04:48:24

A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gain access to response header co...

  • EPSS 0.71%
  • Veröffentlicht 25.03.2019 19:29:02
  • Zuletzt bearbeitet 21.11.2024 04:48:23

A permission issue was found in Elasticsearch versions before 5.6.15 and 6.6.1 when Field Level Security and Document Level Security are disabled and the _aliases, _shrink, or _split endpoints are used . If the elasticsearch.yml file has xpack.securi...

  • EPSS 0.31%
  • Veröffentlicht 20.12.2018 22:29:00
  • Zuletzt bearbeitet 21.11.2024 03:54:09

Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a policy allowing external network access has been added to Elasticsearch's Java Security Manager then an attacker could send a spec...

  • EPSS 0.9%
  • Veröffentlicht 20.12.2018 22:29:00
  • Zuletzt bearbeitet 21.11.2024 03:54:09

Elasticsearch Security versions 6.4.0 to 6.4.2 contain an error in the way request headers are applied to requests when using the Active Directory, LDAP, Native, or File realms. A request may receive headers intended for another request if the same u...

  • EPSS 0.86%
  • Veröffentlicht 19.09.2018 19:29:01
  • Zuletzt bearbeitet 21.11.2024 04:06:07

Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured via the API. The Elasticsearch _cluster/settings API, when queried, could leak sensitive configuration informati...

  • EPSS 0.4%
  • Veröffentlicht 19.09.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 04:06:06

In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameters are set using the _snapshot API they can be exposed as plain text by users able to query the _snapshot AP...