Vulnerabilities > Elastic > High

DATE CVE VULNERABILITY TITLE RISK
2024-02-07 CVE-2024-23448 Information Exposure Through Log Files vulnerability in Elastic APM Server
An issue was discovered whereby APM Server could log at ERROR level, a response from Elasticsearch indicating that indexing the document failed and that response would contain parts of the original document.
network
low complexity
elastic CWE-532
7.5
2023-12-05 CVE-2023-46674 Deserialization of Untrusted Data vulnerability in Elastic Elasticsearch
An issue was identified that allowed the unsafe deserialization of java objects from hadoop or spark configuration properties that could have been modified by authenticated users.
local
low complexity
elastic CWE-502
7.8
2023-11-22 CVE-2023-46673 Improper Handling of Exceptional Conditions vulnerability in Elastic Elasticsearch
It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.
network
low complexity
elastic CWE-755
7.5
2023-11-22 CVE-2021-37937 Unspecified vulnerability in Elastic Elasticsearch
An issue was found with how API keys are created with the Fleet-Server service account.
network
low complexity
elastic
8.8
2023-11-22 CVE-2021-37942 Unspecified vulnerability in Elastic APM Java Agent
A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious plugin to an application running the APM Java agent.
local
low complexity
elastic
7.8
2023-11-22 CVE-2021-22142 Unspecified vulnerability in Elastic Kibana
Kibana contains an embedded version of the Chromium browser that the Reporting feature uses to generate the downloadable reports.
network
low complexity
elastic
8.8
2023-11-22 CVE-2021-22150 Code Injection vulnerability in Elastic Kibana
It was discovered that a user with Fleet admin permissions could upload a malicious package.
network
low complexity
elastic CWE-94
7.2
2023-10-26 CVE-2023-31418 Resource Exhaustion vulnerability in Elastic Elasticsearch
An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer.
network
low complexity
elastic CWE-400
7.5
2023-10-26 CVE-2023-31419 Out-of-bounds Write vulnerability in Elastic Elasticsearch
A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service.
network
low complexity
elastic CWE-787
7.5
2023-10-26 CVE-2023-31421 Improper Certificate Validation vulnerability in Elastic products
It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whether the server certificate is valid for the target IP address; however, certificate signature validation is still performed.
network
low complexity
elastic CWE-295
7.5