Vulnerabilidades em Elastic

352 resultados
Análise Vexday

Com 233 CVEs catalogadas, o ecossistema Elastic apresenta taxa de exploração ativa em linha com a média geral do catálogo, o que não elimina pontos de atenção relevantes. O CVE-2019-7609, única entrada confirmada no CISA KEV, carrega EPSS de 0,9534 — valor extremamente elevado que indica alta probabilidade de exploração ativa e deve ser prioridade absoluta para equipes que ainda não aplicaram a correção correspondente. O tipo de falha mais frequente, CWE-79 (Cross-Site Scripting), sugere que controles de sanitização de entrada e saída merecem atenção sistemática no ciclo de desenvolvimento e hardening das implantações. As 17 CVEs surgidas nos últimos 90 dias e a existência de 3 vulnerabilidades com PoC pública reforçam a necessidade de monitoramento contínuo, especialmente em ambientes expostos.

CVE-2026-72670HIGHExposure of Sensitive Information to an Unauthorized Actor in Kibana Leading to Disclosure of Fleet Proxy CredentialsEPSS 0.3%CVE-2026-63138MEDIUMImproper Neutralization of Special Elements in Data Query Logic in Kibana Leading to Information DisclosureEPSS 0.3%CVE-2023-46672HIGHLogstash Insertion of Sensitive Information into Log FileEPSS 0.3%CVE-2024-23442MEDIUMKibana open redirect issueEPSS 0.3%CVE-2026-72642HIGHUse of Out-of-range Pointer Offset in the Elasticsearch Machine Learning Native Inference ProcessEPSS 0.3%CVE-2026-63143MEDIUMMissing Authorization in Kibana Leading to Unauthorized Information DisclosureEPSS 0.3%CVE-2026-42400MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-72628MEDIUMImproper Handling of Highly Compressed Data in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-42399MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-72678MEDIUMMemory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of ServiceEPSS 0.3%CVE-2026-56145MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceEPSS 0.3%CVE-2026-78586MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-72679MEDIUMUncontrolled Recursion in Elasticsearch Leading to Denial of ServiceEPSS 0.3%CVE-2026-49089MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2024-11390MEDIUMKibana Unrestricted Upload of File with Dangerous Type Can Lead to XSSEPSS 0.3%CVE-2026-56147HIGHAuthorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Information Disclosure and Case Attachment Integrity CompromiseEPSS 0.3%CVE-2025-25016MEDIUMKibana Unrestricted Upload of FileEPSS 0.3%CVE-2026-26936MEDIUMInefficient Regular Expression Complexity in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2023-31421MEDIUMBeats, Elastic Agent, APM Server, and Fleet Server Improper Certificate Validation issueEPSS 0.3%CVE-2025-68384MEDIUMElasticsearch Allocation of Resources Without Limits or ThrottlingEPSS 0.3%