Elastic

Elastic Cloud Enterprise

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.1%
  • Veröffentlicht 28.06.2024 05:15:11
  • Zuletzt bearbeitet 21.11.2024 09:23:32

It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subsequently used to create new API keys that have elevated privileges.

  • EPSS 0.55%
  • Veröffentlicht 26.10.2023 18:15:08
  • Zuletzt bearbeitet 21.11.2024 08:01:49

An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. The ...

  • EPSS 0.24%
  • Veröffentlicht 28.09.2022 20:15:11
  • Zuletzt bearbeitet 21.05.2025 15:15:56

A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in deployment logs in the Logging and Monitoring cluster.

  • EPSS 0.28%
  • Veröffentlicht 25.08.2022 18:15:09
  • Zuletzt bearbeitet 21.11.2024 06:49:10

A flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwords and Elasticsearch keystore settings values in logs such as the audit log or deployment logs in the Logging and Monitoring clus...

  • EPSS 0.22%
  • Veröffentlicht 19.09.2018 19:29:01
  • Zuletzt bearbeitet 21.11.2024 04:06:07

In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invalid roles token. An attacker with access to the previous runner ID and IP address of the coordinator-host coul...

  • EPSS 0.13%
  • Veröffentlicht 19.09.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 04:06:06

In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 a default master encryption key is used in the process of granting ZooKeeper access to Elasticsearch clusters. Unless explicitly overwritten, this master key is predictable across all ECE depl...

  • EPSS 0.19%
  • Veröffentlicht 19.09.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 04:06:06

Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exception conditions would result in encryption keys, passwords, and other security sensitive headers being leaked to...