Show filters
185 Total Results
Displaying 91-100 of 185
Sort by:
Attacker Value
Unknown

CVE-2021-22140

Disclosure Date: May 13, 2021 (last updated February 22, 2025)
Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta feature. Using this vector, an attacker whose website is being crawled by App Search could craft a malicious sitemap.xml to traverse the filesystem of the host running the instance and obtain sensitive files.
Attacker Value
Unknown

CVE-2021-22134

Disclosure Date: March 08, 2021 (last updated February 22, 2025)
A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query against a recently updated document. This affects documents that have been updated and not yet refreshed in the index. This could result in the search disclosing the existence of documents and fields the attacker should not be able to view.
Attacker Value
Unknown

CVE-2020-7021

Disclosure Date: February 10, 2021 (last updated February 22, 2025)
Elasticsearch versions before 7.10.0 and 6.8.14 have an information disclosure issue when audit logging and the emit_request_body option is enabled. The Elasticsearch audit log could contain sensitive information such as password hashes or authentication tokens. This could allow an Elasticsearch administrator to view these details.
Attacker Value
Unknown

CVE-2021-22133

Disclosure Date: February 10, 2021 (last updated February 22, 2025)
The Elastic APM agent for Go versions before 1.11.0 can leak sensitive HTTP header information when logging the details during an application panic. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an application panic it is possible the headers will not be sanitized before being sent.
Attacker Value
Unknown

CVE-2021-22132

Disclosure Date: January 14, 2021 (last updated February 22, 2025)
Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This issue is fixed in Elasticsearch 7.10.2
Attacker Value
Unknown

CVE-2020-27816

Disclosure Date: December 02, 2020 (last updated February 22, 2025)
The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it is possible to replace the original openshift-logging console link (kibana console) to different one, created based on the new CR for the new kibana resource. This could lead to an arbitrary URL redirection or the openshift-logging console link damage. This flaw affects elasticsearch-operator-container versions before 4.7.
Attacker Value
Unknown

CVE-2020-7020

Disclosure Date: October 22, 2020 (last updated February 22, 2025)
Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain complex queries. This could result in the search disclosing the existence of documents the attacker should not be able to view. This could result in an attacker gaining additional insight into potentially sensitive indices.
Attacker Value
Unknown

CVE-2020-7019

Disclosure Date: August 18, 2020 (last updated February 22, 2025)
In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security. If a user runs the same query another more privileged user recently ran, the scrolling search can leak fields that should be hidden. This could result in an attacker gaining additional permissions against a restricted index.
Attacker Value
Unknown

CVE-2020-7018

Disclosure Date: August 18, 2020 (last updated February 22, 2025)
Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, they will be able to view the administrator API credentials. These credentials could allow the developer user to conduct operations with the same permissions of the App Search administrator.
Attacker Value
Unknown

CVE-2020-7017

Disclosure Date: July 27, 2020 (last updated February 21, 2025)
In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive information or perform destructive actions on behalf of Kibana users who view the region map visualization.