Vulnerabilities > Elastic > Elasticsearch > High

DATE CVE VULNERABILITY TITLE RISK
2023-12-05 CVE-2023-46674 Deserialization of Untrusted Data vulnerability in Elastic Elasticsearch
An issue was identified that allowed the unsafe deserialization of java objects from hadoop or spark configuration properties that could have been modified by authenticated users.
local
low complexity
elastic CWE-502
7.8
2023-11-22 CVE-2023-46673 Improper Handling of Exceptional Conditions vulnerability in Elastic Elasticsearch
It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.
network
low complexity
elastic CWE-755
7.5
2023-11-22 CVE-2021-37937 Unspecified vulnerability in Elastic Elasticsearch
An issue was found with how API keys are created with the Fleet-Server service account.
network
low complexity
elastic
8.8
2023-10-26 CVE-2023-31418 Resource Exhaustion vulnerability in Elastic Elasticsearch
An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer.
network
low complexity
elastic CWE-400
7.5
2023-10-26 CVE-2023-31419 Out-of-bounds Write vulnerability in Elastic Elasticsearch
A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service.
network
low complexity
elastic CWE-787
7.5
2022-06-06 CVE-2022-23712 Unspecified vulnerability in Elastic Elasticsearch
A Denial of Service flaw was discovered in Elasticsearch.
network
low complexity
elastic
7.5
2021-07-21 CVE-2021-22146 Unspecified vulnerability in Elastic Elasticsearch 7.13.3
All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters.
network
low complexity
elastic
7.5
2020-06-03 CVE-2020-7014 Improper Privilege Management vulnerability in Elastic Elasticsearch
The fix for CVE-2020-7009 was found to be incomplete.
network
low complexity
elastic CWE-269
8.8
2020-03-31 CVE-2020-7009 Improper Privilege Management vulnerability in Elastic Elasticsearch
Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys.
network
low complexity
elastic CWE-269
8.8
2019-03-25 CVE-2019-7611 Unspecified vulnerability in Elastic Elasticsearch
A permission issue was found in Elasticsearch versions before 5.6.15 and 6.6.1 when Field Level Security and Document Level Security are disabled and the _aliases, _shrink, or _split endpoints are used .
network
high complexity
elastic
8.1