Vulnerabilities > Elastic > Elasticsearch > 7.13.3

DATE CVE VULNERABILITY TITLE RISK
2023-12-05 CVE-2023-46674 Deserialization of Untrusted Data vulnerability in Elastic Elasticsearch
An issue was identified that allowed the unsafe deserialization of java objects from hadoop or spark configuration properties that could have been modified by authenticated users.
local
low complexity
elastic CWE-502
7.8
2023-11-22 CVE-2023-46673 Improper Handling of Exceptional Conditions vulnerability in Elastic Elasticsearch
It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.
network
low complexity
elastic CWE-755
7.5
2023-11-22 CVE-2021-37937 Unspecified vulnerability in Elastic Elasticsearch
An issue was found with how API keys are created with the Fleet-Server service account.
network
low complexity
elastic
8.8
2023-10-26 CVE-2023-31417 Information Exposure Through Log Files vulnerability in Elastic Elasticsearch
Elasticsearch generally filters out sensitive information and credentials before logging to the audit log.
local
low complexity
elastic CWE-532
4.4
2023-10-26 CVE-2023-31418 Resource Exhaustion vulnerability in Elastic Elasticsearch
An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer.
network
low complexity
elastic CWE-400
7.5
2023-10-26 CVE-2023-31419 Out-of-bounds Write vulnerability in Elastic Elasticsearch
A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service.
network
low complexity
elastic CWE-787
7.5
2021-09-15 CVE-2021-22147 Missing Authorization vulnerability in Elastic Elasticsearch
Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots.
network
low complexity
elastic CWE-862
6.5
2021-07-21 CVE-2021-22145 Information Exposure Through an Error Message vulnerability in multiple products
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting.
network
low complexity
elastic oracle CWE-209
4.0
2021-07-21 CVE-2021-22146 Unspecified vulnerability in Elastic Elasticsearch 7.13.3
All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters.
network
low complexity
elastic
5.0