Vulnerabilities > Elastic

DATE CVE VULNERABILITY TITLE RISK
2019-10-01 CVE-2019-7618 Path Traversal vulnerability in Elastic Kibana 7.3.0/7.3.1/7.3.2
A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2.
network
elastic CWE-22
3.5
2019-08-22 CVE-2019-7617 Improper Input Validation vulnerability in Elastic APM Agent
When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw if a remote attacker can control the proxy header.
network
low complexity
elastic CWE-20
6.4
2019-07-30 CVE-2019-7616 Server-Side Request Forgery (SSRF) vulnerability in Elastic Kibana
Kibana versions before 6.8.2 and 7.2.1 contain a server side request forgery (SSRF) flaw in the graphite integration for Timelion visualizer.
network
low complexity
elastic CWE-918
4.9
2019-07-30 CVE-2019-7615 Improper Certificate Validation vulnerability in Elastic Apm-Agent-Ruby
A TLS certificate validation flaw was found in Elastic APM agent for Ruby versions before 2.9.0.
network
high complexity
elastic CWE-295
7.4
2019-07-30 CVE-2019-7614 Race Condition vulnerability in Elastic Elasticsearch
A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request.
network
high complexity
elastic CWE-362
5.9
2019-03-25 CVE-2019-7613 Improper Input Validation vulnerability in Elastic Winlogbeat
Winlogbeat versions before 5.6.16 and 6.6.2 had an insufficient logging flaw.
network
low complexity
elastic CWE-20
5.0
2019-03-25 CVE-2019-7612 Credentials Management vulnerability in multiple products
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs.
network
low complexity
elastic netapp CWE-255
5.0
2019-03-25 CVE-2019-7611 Unspecified vulnerability in Elastic Elasticsearch
A permission issue was found in Elasticsearch versions before 5.6.15 and 6.6.1 when Field Level Security and Document Level Security are disabled and the _aliases, _shrink, or _split endpoints are used .
network
elastic
6.8
2019-03-25 CVE-2019-7610 Command Injection vulnerability in Elastic Kibana
Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger.
network
elastic CWE-77
critical
9.3
2019-03-25 CVE-2019-7609 Code Injection vulnerability in multiple products
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer.
network
low complexity
elastic redhat CWE-94
critical
10.0