Exposição de Elasticsearch

Search engines
73
score de exposição
10.518
sites usam
0
em exploração
0
críticos
Análise Vexday

O histórico de vulnerabilidades do Elasticsearch reúne 43 CVEs catalogadas, sem registros de severidade crítica e sem novas ocorrências nos últimos 90 dias, o que indica um perfil de risco relativamente estável no curto prazo. A taxa de exploração ativa é de 0,0% — abaixo da média geral do catálogo CISA KEV —, embora esse dado deva ser interpretado com cautela dado o EPSS elevado de 0,76 observado para CVE-2021-22145, que permanece como a vulnerabilidade de maior risco no conjunto. Essa CVE, classificada sob CWE-200 (exposição indevida de informações), reflete o padrão de falha mais recorrente na tecnologia: problemas de controle de acesso a dados sensíveis. Equipes de segurança devem priorizar a verificação do status de correção dessa vulnerabilidade específica, especialmente em instâncias expostas a redes não confiáveis.

CVEs

70 resultados
CVE-2026-72679MEDIUMUncontrolled Recursion in Elasticsearch Leading to Denial of ServiceEPSS 0.5%CVE-2026-72678MEDIUMMemory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of ServiceEPSS 0.5%CVE-2024-12539MEDIUMElasticsearch Incorrect AuthorizationEPSS 0.5%CVE-2021-22138—In Logstash versions after 6.4.0 and before 6.8.15 and 7.12.0 a TLS certificate validation flaw was found in the monitoring feature. When spEPSS 0.5%CVE-2024-23445MEDIUMElasticsearch Remote Cluster Search Cross Cluster API Key insufficient restrictionsEPSS 0.5%CVE-2023-49921MEDIUMAn issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level. This could lead to raw cEPSS 0.4%CVE-2026-56143MEDIUMAllocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of ServiceEPSS 0.4%CVE-2026-49090MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceEPSS 0.4%CVE-2026-63136MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceEPSS 0.4%CVE-2026-63140MEDIUMReachable Assertion in Elasticsearch Leading to Denial of ServiceEPSS 0.4%CVE-2026-63144MEDIUMUncontrolled Recursion in Elasticsearch Leading to Denial of ServiceEPSS 0.4%CVE-2026-63263MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceEPSS 0.4%CVE-2026-72684MEDIUMAllocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of ServiceEPSS 0.4%CVE-2026-72645MEDIUMMemory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of ServiceEPSS 0.4%CVE-2026-72647MEDIUMUncontrolled Recursion in Elasticsearch Leading to Denial of ServiceEPSS 0.4%CVE-2026-72656MEDIUMMemory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of ServiceEPSS 0.4%CVE-2026-72687MEDIUMMemory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of ServiceEPSS 0.4%CVE-2026-72638MEDIUMUncontrolled Recursion in Elasticsearch Leading to Denial of ServiceEPSS 0.4%CVE-2026-72639MEDIUMMemory Allocation with Excessive Size Value in Elasticsearch Highlighting Leading to Denial of ServiceEPSS 0.4%CVE-2026-72636MEDIUMUncontrolled Recursion in Elasticsearch Wildcard Matching Leading to Denial of ServiceEPSS 0.4%