Show filters
185 Total Results
Displaying 141-150 of 185
Sort by:
Attacker Value
Unknown
CVE-2015-5377
Disclosure Date: March 06, 2018 (last updated November 08, 2023)
Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerability
0
Attacker Value
Unknown
CVE-2017-11480
Disclosure Date: December 08, 2017 (last updated November 26, 2024)
Packetbeat versions prior to 5.6.4 are affected by a denial of service flaw in the PostgreSQL protocol handler. If Packetbeat is listening for PostgreSQL traffic and a user is able to send arbitrary network traffic to the monitored port, the attacker could prevent Packetbeat from properly logging other PostgreSQL traffic.
0
Attacker Value
Unknown
CVE-2017-11482
Disclosure Date: December 08, 2017 (last updated November 26, 2024)
The Kibana fix for CVE-2017-8451 was found to be incomplete. With X-Pack installed, Kibana versions before 6.0.1 and 5.6.5 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.
0
Attacker Value
Unknown
CVE-2017-11481
Disclosure Date: December 08, 2017 (last updated November 26, 2024)
Kibana versions prior to 6.0.1 and 5.6.5 had a cross-site scripting (XSS) vulnerability via URL fields that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
0
Attacker Value
Unknown
CVE-2017-11479
Disclosure Date: September 29, 2017 (last updated November 26, 2024)
Kibana versions prior to 5.6.1 had a cross-site scripting (XSS) vulnerability in Timelion that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
0
Attacker Value
Unknown
CVE-2017-8448
Disclosure Date: September 29, 2017 (last updated November 26, 2024)
An error was found in the permission model used by X-Pack Alerting 5.0.0 to 5.6.0 whereby users mapped to certain built-in roles could create a watch that results in that user gaining elevated privileges.
0
Attacker Value
Unknown
CVE-2017-8444
Disclosure Date: September 29, 2017 (last updated November 26, 2024)
The client-forwarder in Elastic Cloud Enterprise versions prior to 1.0.2 do not properly encrypt traffic to ZooKeeper. If an attacker is able to man in the middle (MITM) the traffic between the client-forwarder and ZooKeeper they could potentially obtain sensitive data.
0
Attacker Value
Unknown
CVE-2017-8447
Disclosure Date: September 29, 2017 (last updated November 26, 2024)
An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index' permissions on an index in a cluster, they may be able to issue both delete and index requests against that index.
0
Attacker Value
Unknown
CVE-2017-14730
Disclosure Date: September 25, 2017 (last updated November 26, 2024)
The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls for user-writable directory trees, which allows local users to gain privileges by leveraging access to a $LS_USER account for creation of a hard link.
0
Attacker Value
Unknown
CVE-2017-8446
Disclosure Date: August 18, 2017 (last updated November 26, 2024)
The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vulnerability. A user with the reporting_user role could execute a report with the permissions of another reporting user, possibly gaining access to sensitive data.
0