Show filters
185 Total Results
Displaying 131-140 of 185
Sort by:
Attacker Value
Unknown

CVE-2018-3829

Disclosure Date: September 19, 2018 (last updated November 27, 2024)
In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invalid roles token. An attacker with access to the previous runner ID and IP address of the coordinator-host could add a allocator to an existing ECE install to gain access to other clusters data.
Attacker Value
Unknown

CVE-2018-3827

Disclosure Date: September 19, 2018 (last updated November 27, 2024)
A sensitive data disclosure flaw was found in the Elasticsearch repository-azure (formerly elasticsearch-cloud-azure) plugin. When the repository-azure plugin is set to log at TRACE level Azure credentials can be inadvertently logged.
Attacker Value
Unknown

CVE-2018-3823

Disclosure Date: September 19, 2018 (last updated November 27, 2024)
X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. Users with manage_ml permissions could create jobs containing malicious data as part of their configuration that could allow the attacker to obtain sensitive information from or perform destructive actions on behalf of other ML users viewing the results of the jobs.
Attacker Value
Unknown

CVE-2018-3826

Disclosure Date: September 19, 2018 (last updated November 27, 2024)
In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameters are set using the _snapshot API they can be exposed as plain text by users able to query the _snapshot API.
0
Attacker Value
Unknown

CVE-2018-3818

Disclosure Date: March 30, 2018 (last updated November 26, 2024)
Kibana versions 5.1.1 to 6.1.2 and 5.6.6 had a cross-site scripting (XSS) vulnerability via the colored fields formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
0
Attacker Value
Unknown

CVE-2018-3817

Disclosure Date: March 30, 2018 (last updated November 26, 2024)
When logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log sensitive information.
0
Attacker Value
Unknown

CVE-2018-3820

Disclosure Date: March 30, 2018 (last updated November 26, 2024)
Kibana versions after 6.1.0 and before 6.1.3 had a cross-site scripting (XSS) vulnerability in labs visualizations that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
Attacker Value
Unknown

CVE-2018-3822

Disclosure Date: March 30, 2018 (last updated November 26, 2024)
X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM traversal. An attacker might have been able to impersonate a legitimate user if the SAML Identity Provider allows for self registration with arbitrary identifiers and the attacker can register an account which an identifier that shares a suffix with a legitimate account. Both of those conditions must be true in order to exploit this flaw.
Attacker Value
Unknown

CVE-2018-3821

Disclosure Date: March 30, 2018 (last updated November 26, 2024)
Kibana versions after 5.1.1 and before 5.6.7 and 6.1.3 had a cross-site scripting (XSS) vulnerability in the tag cloud visualization that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
Attacker Value
Unknown

CVE-2018-3819

Disclosure Date: March 30, 2018 (last updated November 26, 2024)
The fix in Kibana for ESA-2017-23 was incomplete. With X-Pack security enabled, Kibana versions before 6.1.3 and 5.6.7 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.
0