Vulnerabilities > Elastic > High

DATE CVE VULNERABILITY TITLE RISK
2022-06-06 CVE-2022-23712 Unspecified vulnerability in Elastic Elasticsearch
A Denial of Service flaw was discovered in Elasticsearch.
network
low complexity
elastic
7.5
2021-12-08 CVE-2021-37941 Improper Privilege Management vulnerability in Elastic APM Agent
A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious file to an application running with the APM Java agent.
local
low complexity
elastic CWE-269
7.8
2021-09-15 CVE-2021-22148 Incorrect Permission Assignment for Critical Resource vulnerability in Elastic Enterprise Search
Elastic Enterprise Search App Search versions before 7.14.0 was vulnerable to an issue where API keys were not bound to the same engines as their creator.
network
low complexity
elastic CWE-732
8.8
2021-09-15 CVE-2021-22149 Missing Authorization vulnerability in Elastic Enterprise Search
Elastic Enterprise Search App Search versions before 7.14.0 are vulnerable to an issue where API keys were missing authorization via an alternate route.
network
low complexity
elastic CWE-862
8.8
2021-07-21 CVE-2021-22146 Unspecified vulnerability in Elastic Elasticsearch 7.13.3
All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters.
network
low complexity
elastic
7.5
2021-05-13 CVE-2021-22140 XXE vulnerability in Elastic APP Search 7.11.0/7.11.1
Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta feature.
network
low complexity
elastic CWE-611
7.5
2020-08-18 CVE-2020-7018 Improper Privilege Management vulnerability in Elastic Enterprise Search
Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface.
network
low complexity
elastic CWE-269
8.8
2020-06-03 CVE-2020-7014 Improper Privilege Management vulnerability in Elastic Elasticsearch
The fix for CVE-2020-7009 was found to be incomplete.
network
low complexity
elastic CWE-269
8.8
2020-06-03 CVE-2020-7013 Code Injection vulnerability in multiple products
Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB.
network
low complexity
elastic redhat CWE-94
7.2
2020-06-03 CVE-2020-7012 Code Injection vulnerability in Elastic Kibana
Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant.
network
low complexity
elastic CWE-94
8.8