Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
elasticsearch elasticsearch vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2015-1427
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script....
Elasticsearch Elasticsearch 1.4.0
Elasticsearch Elasticsearch 1.4.1
Elasticsearch Elasticsearch 1.4.2
Elasticsearch Elasticsearch
2 EDB exploits available
1 Metasploit module available
1 Nmap script available
47 Github repositories available
9 Articles available
7.8
CVSSv3
CVE-2017-14730
The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls for user-writable directory trees, which allows local users to gain privileges by leveraging access to a $LS_USER account for creation of a hard link....
Elasticsearch Logstash 5.0.2
Elasticsearch Logstash 5.1.2
Elasticsearch Logstash 5.4.2
Elasticsearch Logstash 5.5.0
Elasticsearch Logstash 5.2.1
Elasticsearch Logstash 5.3.0
Elasticsearch Logstash 5.3.1
Elasticsearch Logstash 5.3.2
Elasticsearch Logstash 5.5.1
Elasticsearch Logstash 5.5.2
Elasticsearch Logstash 5.6.0
Elasticsearch Logstash 5.0.0
Elasticsearch Logstash 5.0.1
Elasticsearch Logstash 5.1.1
Elasticsearch Logstash 5.2.0
Elasticsearch Logstash 5.4.1
Elasticsearch Logstash 5.4.3
NA
CVE-2015-3337
Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors....
Elasticsearch Elasticsearch 1.5.0
Elasticsearch Elasticsearch 1.5.1
Elasticsearch Elasticsearch
1 EDB exploit available
11 Github repositories available
NA
CVE-2014-6439
Cross-site scripting (XSS) vulnerability in the CORS functionality in Elasticsearch before 1.4.0.Beta1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors....
Elasticsearch Elasticsearch
5.9
CVSSv3
CVE-2015-5619
Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might allow attackers to obtain sensitive information via a man-in-the-middle attack....
Elastic Logstash 1.4.0
Elastic Logstash 1.4.2
Elasticsearch Logstash 1.5.0
Elasticsearch Logstash 1.5.1
Elastic Logstash 1.4.1
Elasticsearch Logstash 1.5.2
Elasticsearch Logstash 1.5.3
Elasticsearch Logstash 1.4.3
Elasticsearch Logstash 1.4.4
NA
CVE-2014-3120
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the...
Elasticsearch Elasticsearch
2 EDB exploits available
1 Metasploit module available
55 Github repositories available
5 Articles available
NA
CVE-2015-5531
Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unspecified vectors related to snapshot API calls....
Elasticsearch Elasticsearch
1 EDB exploit available
1 Metasploit module available
9 Github repositories available
7.5
CVSSv3
CVE-2015-4165
The snapshot API in Elasticsearch before 1.6.0 when another application exists on the system that can read Lucene files and execute code from them, is accessible by the attacker, and the Java VM on which Elasticsearch is running can write to a location that the other application...
Elasticsearch Elasticsearch 1.5.2
5.3
CVSSv3
CVE-2017-8446
The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vulnerability. A user with the reporting_user role could execute a report with the permissions of another reporting user, possibly...
Elasticsearch X-pack
Elasticsearch X-pack Reporting
5.9
CVSSv3
CVE-2017-8444
The client-forwarder in Elastic Cloud Enterprise versions prior to 1.0.2 do not properly encrypt traffic to ZooKeeper. If an attacker is able to man in the middle (MITM) the traffic between the client-forwarder and ZooKeeper they could potentially obtain sensitive data....
Elasticsearch Cloud Enterprise 1.0.1
Elasticsearch Cloud Enterprise 1.0.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
log injection
CVE-2022-31656
CVE-2022-37006
CVE-2022-34713
wireless
CVE-2022-37007
SQL injection
CVE-2022-32429
CVE-2022-37024
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »