Vulnerabilities > Elastic > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-12-08 | CVE-2017-11481 | Cross-site Scripting vulnerability in Elastic Kibana Kibana versions prior to 6.0.1 and 5.6.5 had a cross-site scripting (XSS) vulnerability via URL fields that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users. | 6.1 |
2017-09-29 | CVE-2017-8447 | Improper Privilege Management vulnerability in Elastic X-Pack An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. | 6.5 |
2017-09-29 | CVE-2017-11479 | Cross-site Scripting vulnerability in multiple products Kibana versions prior to 5.6.1 had a cross-site scripting (XSS) vulnerability in Timelion that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users. | 6.1 |
2017-08-18 | CVE-2017-8445 | Improper Certificate Validation vulnerability in Elastic X-Pack An error was found in the X-Pack Security TLS trust manager for versions 5.0.0 to 5.5.1. | 5.5 |
2017-08-09 | CVE-2015-5619 | Improper Certificate Validation vulnerability in multiple products Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might allow attackers to obtain sensitive information via a man-in-the-middle attack. | 5.9 |
2017-07-07 | CVE-2017-8442 | Information Exposure vulnerability in Elastic X-Pack Elasticsearch X-Pack Security versions 5.0.0 to 5.4.3, when enabled, can result in the Elasticsearch _nodes API leaking sensitive configuration information, such as the paths and passphrases of SSL keys that were configured as part of an authentication realm. | 6.5 |
2017-06-30 | CVE-2017-8443 | Information Exposure vulnerability in Elastic Kibana In Kibana X-Pack security versions prior to 5.4.3 if a Kibana user opens a crafted Kibana URL the result could be a redirect to an improperly initialized Kibana login screen. | 6.5 |
2017-06-16 | CVE-2017-8451 | Open Redirect vulnerability in Elastic Kibana With X-Pack installed, Kibana versions before 5.3.1 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website. | 6.1 |
2017-06-16 | CVE-2017-8449 | Information Exposure vulnerability in Elastic X-Pack 5.2.0/5.2.1/5.2.2 X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules used a mix of grant and exclude rules when merging multiple rules with field level security rules for the same index. | 5.9 |
2017-06-16 | CVE-2016-10366 | Cross-site Scripting vulnerability in Elastic Kibana Kibana versions after and including 4.3 and before 4.6.2 are vulnerable to a cross-site scripting (XSS) attack. | 6.1 |