Show filters
185 Total Results
Displaying 81-90 of 185
Sort by:
Attacker Value
Unknown

CVE-2021-22148

Disclosure Date: September 15, 2021 (last updated February 23, 2025)
Elastic Enterprise Search App Search versions before 7.14.0 was vulnerable to an issue where API keys were not bound to the same engines as their creator. This could lead to a less privileged user gaining access to unauthorized engines.
Attacker Value
Unknown

CVE-2021-22144

Disclosure Date: July 26, 2021 (last updated February 23, 2025)
In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit arbitrary queries to Elasticsearch could create a malicious Grok query that will crash the Elasticsearch node.
Attacker Value
Unknown

CVE-2021-22145

Disclosure Date: July 21, 2021 (last updated February 23, 2025)
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer. This buffer could contain sensitive information such as Elasticsearch documents or authentication details.
Attacker Value
Unknown

CVE-2021-22146

Disclosure Date: July 21, 2021 (last updated February 23, 2025)
All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the default setting the anonymous user has no permissions and is unable to successfully query any Elasticsearch APIs, an attacker could leverage the anonymous user to gain insight into certain details of a deployed cluster.
Attacker Value
Unknown

CVE-2020-10743

Disclosure Date: June 02, 2021 (last updated February 22, 2025)
It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercept and manipulate requests. This flaw allows an attacker to trick a user into performing arbitrary actions in OCP's distribution of Kibana, such as clickjacking.
Attacker Value
Unknown

CVE-2021-22139

Disclosure Date: May 13, 2021 (last updated February 22, 2025)
Kibana versions before 7.12.1 contain a denial of service vulnerability was found in the webhook actions due to a lack of timeout or a limit on the request size. An attacker with permissions to create webhook actions could drain the Kibana host connection pool, making Kibana unavailable for all other users.
Attacker Value
Unknown

CVE-2021-22135

Disclosure Date: May 13, 2021 (last updated February 22, 2025)
Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API when Document and Field Level Security are enabled. The suggester and profile API are normally disabled for an index when document level security is enabled on the index. Certain queries are able to enable the profiler and suggester which could lead to disclosing the existence of documents and fields the attacker should not be able to view.
Attacker Value
Unknown

CVE-2021-22136

Disclosure Date: May 13, 2021 (last updated February 22, 2025)
In Kibana versions before 7.12.0 and 6.8.15 a flaw in the session timeout was discovered where the xpack.security.session.idleTimeout setting is not being respected. This was caused by background polling activities unintentionally extending authenticated users sessions, preventing a user session from timing out.
Attacker Value
Unknown

CVE-2021-22138

Disclosure Date: May 13, 2021 (last updated February 22, 2025)
In Logstash versions after 6.4.0 and before 6.8.15 and 7.12.0 a TLS certificate validation flaw was found in the monitoring feature. When specifying a trusted server CA certificate Logstash would not properly verify the certificate returned by the monitoring server. This could result in a man in the middle style attack against the Logstash monitoring data.
Attacker Value
Unknown

CVE-2021-22137

Disclosure Date: May 13, 2021 (last updated February 22, 2025)
In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosure flaw was found when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain cross-cluster search queries. This could result in the search disclosing the existence of documents the attacker should not be able to view. This could result in an attacker gaining additional insight into potentially sensitive indices.