Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Elastic

128 known vulnerabilities

7
CRITICAL
25
HIGH
86
MEDIUM

Top Products

kibana 70 elasticsearch 17 logstash 9 x-pack 9 elastic cloud enterprise 3 elasticsearch x-pack 2 kibana x-pack 2 logstash x-pack 2 endpoint security 1 fleet server 1
118 CVEs · Page 3/3
7.5
CVE-2017-8452

Kibana versions prior to 5.2.1 configured for SSL client access, file descriptors will fail to be cleaned up after certa

6.1
CVE-2017-8451

With X-Pack installed, Kibana versions before 5.3.1 have an open redirect vulnerability on the login page that would ena

7.5
CVE-2017-8450

X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users wi

5.9
CVE-2017-8449

X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules

6.1
CVE-2016-10366

Kibana versions after and including 4.3 and before 4.6.2 are vulnerable to a cross-site scripting (XSS) attack.

6.1
CVE-2016-10365

Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link

6.5
CVE-2016-10364

With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings an

7.5
CVE-2016-10363

Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5,

7.5
CVE-2016-1000222

Logstash prior to version 2.1.2, the CSV output can be attacked via engineered input that will create malicious formulas

7.5
CVE-2016-1000221

Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could co

6.1
CVE-2016-1000220

Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScr

7.5
CVE-2016-1000219

Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers coul

8.8
CVE-2016-1000218

Kibana Reporting plugin version 2.4.0 is vulnerable to a CSRF vulnerability that could allow an attacker to generate sup

6.1
CVE-2015-9056

Kibana versions prior to 4.1.3 and 4.2.1 are vulnerable to a XSS attack.

4.3
CVE-2017-8441

Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to inde

6.1
CVE-2017-8440

Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow a

6.1
CVE-2017-8439

Kibana version 5.4.0 was affected by a Cross Site Scripting (XSS) bug in the Time Series Visual Builder. This bug could

8.8
CVE-2017-8438

Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality. This bug

Frequently Asked Questions

How many CVEs affect Elastic?

Elastic has 128 CVE records in our database, including 8 critical and 26 high severity vulnerabilities. 1 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Elastic vulnerabilities?

Elastic has 8 critical severity (CVSS 9.0+) and 26 high severity (CVSS 7.0-8.9) vulnerabilities. 1 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Elastic vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Elastic products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Elastic Vulnerabilities

CyberStrike scans your infrastructure for Elastic vulnerabilities and provides real-time remediation guidance.

Get Started