Show filters
185 Total Results
Displaying 111-120 of 185
Sort by:
Attacker Value
Unknown

CVE-2019-7619

Disclosure Date: October 30, 2019 (last updated November 27, 2024)
Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker could send a specially crafted request and determine if a username exists in the Elasticsearch native realm.
Attacker Value
Unknown

CVE-2019-7618

Disclosure Date: October 01, 2019 (last updated November 27, 2024)
A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is possible to read arbitrary files from the local filesystem of the Kibana instance running Code with the permission of the Kibana system user.
Attacker Value
Unknown

CVE-2019-7617

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw if a remote attacker can control the proxy header. This could result in an attacker redirecting collected APM data to a proxy of their choosing.
0
Attacker Value
Unknown

CVE-2019-7616

Disclosure Date: July 30, 2019 (last updated November 27, 2024)
Kibana versions before 6.8.2 and 7.2.1 contain a server side request forgery (SSRF) flaw in the graphite integration for Timelion visualizer. An attacker with administrative Kibana access could set the timelion:graphite.url configuration option to an arbitrary URL. This could possibly lead to an attacker accessing external URL resources as the Kibana process on the host system.
Attacker Value
Unknown

CVE-2019-7614

Disclosure Date: July 30, 2019 (last updated November 27, 2024)
A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gain access to response header containing sensitive data from another user.
Attacker Value
Unknown

CVE-2019-7615

Disclosure Date: July 30, 2019 (last updated November 27, 2024)
A TLS certificate validation flaw was found in Elastic APM agent for Ruby versions before 2.9.0. When specifying a trusted server CA certificate via the 'server_ca_cert' setting, the Ruby agent would not properly verify the certificate returned by the APM server. This could result in a man in the middle style attack against the Ruby agent.
Attacker Value
Unknown

CVE-2019-7610

Disclosure Date: March 25, 2019 (last updated November 27, 2024)
Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.security.audit.enabled set to true, an attacker could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
0
Attacker Value
Unknown

CVE-2019-7608

Disclosure Date: March 25, 2019 (last updated November 27, 2024)
Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XSS) vulnerability that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
0
Attacker Value
Unknown

CVE-2019-7612

Disclosure Date: March 25, 2019 (last updated November 27, 2024)
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified as part of the Logstash configuration, the credentials for the URL could be inadvertently logged as part of the error message.
Attacker Value
Unknown

CVE-2019-7613

Disclosure Date: March 25, 2019 (last updated November 27, 2024)
Winlogbeat versions before 5.6.16 and 6.6.2 had an insufficient logging flaw. An attacker able to inject certain characters into a log entry could prevent Winlogbeat from recording the event.