Elastic

Elastic Cloud On Kubernetes

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 02.09.2026 14:43:06
  • Zuletzt bearbeitet 03.09.2026 19:15:08

Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association has been denied by RBAC enforcement, allowing a ...

  • EPSS 0.09%
  • Veröffentlicht 02.09.2026 14:43:04
  • Zuletzt bearbeitet 04.09.2026 16:39:24

Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification of data via Metadata Spoofing (CAPEC-690). An actor holding limited Kubernetes permissions confined to a single namespace could cause attacke...

  • EPSS 0.25%
  • Veröffentlicht 13.08.2026 19:13:43
  • Zuletzt bearbeitet 03.09.2026 18:54:54

The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret references from an annotation on secrets it manages, and it accepts the namespace recorded in each reference without validating that the reference is authorized for the resource be...

  • EPSS 0.28%
  • Veröffentlicht 13.08.2026 19:13:31
  • Zuletzt bearbeitet 04.09.2026 20:16:20

Cleartext Storage of Sensitive Information in an Environment Variable (CWE-526) in Elastic Cloud on Kubernetes (ECK) can lead to information disclosure via Retrieve Embedded Sensitive Data (CAPEC-37). When ECK reconciles a Fleet Server resource that ...

  • EPSS 0.36%
  • Veröffentlicht 26.10.2023 19:15:45
  • Zuletzt bearbeitet 21.11.2024 08:01:49

Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requests to an APM Server being accepted and the data ingested into this APM deployment.

  • EPSS 1.44%
  • Veröffentlicht 03.06.2020 18:15:22
  • Zuletzt bearbeitet 21.11.2024 05:36:29

Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator. If an attacker is able to determine when the current Elastic Stack cluster was deployed they may be able to more easily brute force the...