Elastic
128 known vulnerabilities
Top Products
Kibana versions prior to 5.2.1 configured for SSL client access, file descriptors will fail to be cleaned up after certa
With X-Pack installed, Kibana versions before 5.3.1 have an open redirect vulnerability on the login page that would ena
X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users wi
X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules
Kibana versions after and including 4.3 and before 4.6.2 are vulnerable to a cross-site scripting (XSS) attack.
Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link
With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings an
Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5,
Logstash prior to version 2.1.2, the CSV output can be attacked via engineered input that will create malicious formulas
Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could co
Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScr
Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers coul
Kibana Reporting plugin version 2.4.0 is vulnerable to a CSRF vulnerability that could allow an attacker to generate sup
Kibana versions prior to 4.1.3 and 4.2.1 are vulnerable to a XSS attack.
Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to inde
Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow a
Kibana version 5.4.0 was affected by a Cross Site Scripting (XSS) bug in the Time Series Visual Builder. This bug could
Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality. This bug
Frequently Asked Questions
How many CVEs affect Elastic?
Elastic has 128 CVE records in our database, including 8 critical and 26 high severity vulnerabilities. 1 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Elastic vulnerabilities?
Elastic has 8 critical severity (CVSS 9.0+) and 26 high severity (CVSS 7.0-8.9) vulnerabilities. 1 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Elastic vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Elastic products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Elastic Vulnerabilities
CyberStrike scans your infrastructure for Elastic vulnerabilities and provides real-time remediation guidance.
Get Started