Exposição de Elasticsearch

Search engines
37
score de exposição
13.329
sites usam
0
em exploração
0
críticos
Análise Vexday

O histórico de vulnerabilidades do Elasticsearch reúne 43 CVEs catalogadas, sem registros de severidade crítica e sem novas ocorrências nos últimos 90 dias, o que indica um perfil de risco relativamente estável no curto prazo. A taxa de exploração ativa é de 0,0% — abaixo da média geral do catálogo CISA KEV —, embora esse dado deva ser interpretado com cautela dado o EPSS elevado de 0,76 observado para CVE-2021-22145, que permanece como a vulnerabilidade de maior risco no conjunto. Essa CVE, classificada sob CWE-200 (exposição indevida de informações), reflete o padrão de falha mais recorrente na tecnologia: problemas de controle de acesso a dados sensíveis. Equipes de segurança devem priorizar a verificação do status de correção dessa vulnerabilidade específica, especialmente em instâncias expostas a redes não confiáveis.

CVEs

52 resultados
CVE-2019-7614A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system withEPSS 1.0%CVE-2024-23450MEDIUMElasticsearch Uncontrolled Resource Consumption vulnerabilityEPSS 1.0%CVE-2022-23708A flaw was discovered in Elasticsearch 7.17.0’s upgrade assistant, in which upgrading from version 6.x to 7.x would disable the in-built proEPSS 0.9%CVE-2023-46673MEDIUMIt was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when EPSS 0.8%CVE-2021-37937MEDIUMElasticsearch privilege escalationEPSS 0.7%CVE-2018-3826In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameEPSS 0.7%CVE-2024-23449MEDIUMElasticsearch Uncaught ExceptionEPSS 0.7%CVE-2024-43709MEDIUMElasticsearch allocation of resources without limits or throttling leads to crashEPSS 0.6%CVE-2024-52979MEDIUMElasticsearch Uncontrolled Resource Consumption vulnerabilityEPSS 0.6%CVE-2024-52981MEDIUMAn issue was discovered in Elasticsearch, where a large recursion using the Well-KnownText formatted string with nested GeometryCollection oEPSS 0.5%CVE-2024-37280MEDIUMElasticsearch StackOverflow vulnerabilityEPSS 0.5%CVE-2024-52980MEDIUMElasticsearch Uncontrolled Resource Consumption vulnerabilityEPSS 0.5%CVE-2021-22138In Logstash versions after 6.4.0 and before 6.8.15 and 7.12.0 a TLS certificate validation flaw was found in the monitoring feature. When spEPSS 0.5%CVE-2024-23445MEDIUMElasticsearch Remote Cluster Search Cross Cluster API Key insufficient restrictionsEPSS 0.5%CVE-2023-49921MEDIUMAn issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level. This could lead to raw cEPSS 0.4%CVE-2024-23451MEDIUMElasticsearch Incorrect Authorization in the Remote Cluster Security API key based security modelEPSS 0.4%CVE-2024-12539MEDIUMElasticsearch Incorrect AuthorizationEPSS 0.4%CVE-2026-56148MEDIUMUncontrolled Recursion in Elasticsearch Leading to Denial of ServiceEPSS 0.3%CVE-2025-68390MEDIUMElasticsearch Allocation of Resources Without Limits or ThrottlingEPSS 0.3%CVE-2026-56149MEDIUMAllocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of ServiceEPSS 0.3%