Vulnerabilities > Elasticsearch > High

DATE CVE VULNERABILITY TITLE RISK
2017-09-25 CVE-2017-14730 Incorrect Permission Assignment for Critical Resource vulnerability in Elasticsearch Logstash
The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls for user-writable directory trees, which allows local users to gain privileges by leveraging access to a $LS_USER account for creation of a hard link.
local
low complexity
elasticsearch gentoo CWE-732
7.2
2015-02-17 CVE-2015-1427 Improper Access Control vulnerability in Elasticsearch
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
network
low complexity
elasticsearch CWE-284
7.5