Vulnerabilities > Elastic > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-10-26 CVE-2023-46668 Information Exposure Through Log Files vulnerability in Elastic Endpoint 7.9.0/8.10.3
If Elastic Endpoint (v7.9.0 - v8.10.3) is configured to use a non-default option in which the logging level is explicitly set to debug, and when Elastic Agent is simultaneously configured to collect and send those logs to Elasticsearch, then Elastic Agent API keys can be viewed in Elasticsearch in plaintext.
network
low complexity
elastic CWE-532
critical
9.1
2019-03-25 CVE-2019-7609 Code Injection vulnerability in multiple products
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer.
network
low complexity
elastic redhat CWE-94
critical
10.0
2019-03-25 CVE-2019-7610 Command Injection vulnerability in Elastic Kibana
Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger.
network
elastic CWE-77
critical
9.3
2018-03-30 CVE-2018-3822 Path Traversal vulnerability in Elastic X-Pack 6.2.0/6.2.1/6.2.2
X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM traversal.
network
low complexity
elastic CWE-22
critical
9.8
2018-03-06 CVE-2015-5377 Injection vulnerability in Elastic Elasticsearch
Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol.
network
low complexity
elastic CWE-74
critical
9.8