Vulnerabilities > Elastic > Elasticsearch > 7.10.0

DATE CVE VULNERABILITY TITLE RISK
2023-12-05 CVE-2023-46674 Deserialization of Untrusted Data vulnerability in Elastic Elasticsearch
An issue was identified that allowed the unsafe deserialization of java objects from hadoop or spark configuration properties that could have been modified by authenticated users.
local
low complexity
elastic CWE-502
7.8
2023-11-22 CVE-2023-46673 Improper Handling of Exceptional Conditions vulnerability in Elastic Elasticsearch
It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.
network
low complexity
elastic CWE-755
7.5
2023-10-26 CVE-2023-31417 Information Exposure Through Log Files vulnerability in Elastic Elasticsearch
Elasticsearch generally filters out sensitive information and credentials before logging to the audit log.
local
low complexity
elastic CWE-532
4.4
2023-10-26 CVE-2023-31418 Resource Exhaustion vulnerability in Elastic Elasticsearch
An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer.
network
low complexity
elastic CWE-400
7.5
2023-10-26 CVE-2023-31419 Out-of-bounds Write vulnerability in Elastic Elasticsearch
A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service.
network
low complexity
elastic CWE-787
7.5
2021-07-26 CVE-2021-22144 Uncontrolled Recursion vulnerability in multiple products
In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser.
network
low complexity
elastic oracle CWE-674
4.0
2021-07-21 CVE-2021-22145 Information Exposure Through an Error Message vulnerability in multiple products
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting.
network
low complexity
elastic oracle CWE-209
4.0
2021-03-08 CVE-2021-22134 Incorrect Authorization vulnerability in multiple products
A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used.
network
low complexity
elastic oracle CWE-863
4.3
2021-01-14 CVE-2021-22132 Insufficiently Protected Credentials vulnerability in multiple products
Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API.
network
high complexity
elastic oracle CWE-522
2.1