Vulnerabilities > Elastic > Elasticsearch > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-07-26 CVE-2023-49921 Information Exposure Through Log Files vulnerability in Elastic Elasticsearch
An issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level.
network
low complexity
elastic CWE-532
6.5
2024-06-13 CVE-2024-37280 Out-of-bounds Write vulnerability in Elastic Elasticsearch
A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field mapping of “passthrough” type.
network
low complexity
elastic CWE-787
4.9
2023-10-26 CVE-2023-31417 Information Exposure Through Log Files vulnerability in Elastic Elasticsearch
Elasticsearch generally filters out sensitive information and credentials before logging to the audit log.
local
low complexity
elastic CWE-532
4.4
2022-03-03 CVE-2022-23708 Unspecified vulnerability in Elastic Elasticsearch
A flaw was discovered in Elasticsearch 7.17.0’s upgrade assistant, in which upgrading from version 6.x to 7.x would disable the in-built protections on the security index, allowing authenticated users with “*” index permissions access to this index.
network
low complexity
elastic
4.3
2021-09-15 CVE-2021-22147 Missing Authorization vulnerability in Elastic Elasticsearch
Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots.
network
low complexity
elastic CWE-862
6.5
2021-07-26 CVE-2021-22144 Uncontrolled Recursion vulnerability in multiple products
In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser.
network
low complexity
elastic oracle CWE-674
6.5
2021-07-21 CVE-2021-22145 Information Exposure Through an Error Message vulnerability in multiple products
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting.
network
low complexity
elastic oracle CWE-209
6.5
2021-05-13 CVE-2021-22135 Information Exposure vulnerability in Elastic Elasticsearch
Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API when Document and Field Level Security are enabled.
network
low complexity
elastic CWE-200
5.3
2021-05-13 CVE-2021-22137 Improper Preservation of Permissions vulnerability in Elastic Elasticsearch
In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosure flaw was found when Document or Field Level Security is used.
network
low complexity
elastic CWE-281
5.3
2021-03-08 CVE-2021-22134 Incorrect Authorization vulnerability in multiple products
A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used.
network
low complexity
elastic oracle CWE-863
4.3