Vulnerabilidades em Elastic

352 resultados
Análise Vexday

Com 233 CVEs catalogadas, o ecossistema Elastic apresenta taxa de exploração ativa em linha com a média geral do catálogo, o que não elimina pontos de atenção relevantes. O CVE-2019-7609, única entrada confirmada no CISA KEV, carrega EPSS de 0,9534 — valor extremamente elevado que indica alta probabilidade de exploração ativa e deve ser prioridade absoluta para equipes que ainda não aplicaram a correção correspondente. O tipo de falha mais frequente, CWE-79 (Cross-Site Scripting), sugere que controles de sanitização de entrada e saída merecem atenção sistemática no ciclo de desenvolvimento e hardening das implantações. As 17 CVEs surgidas nos últimos 90 dias e a existência de 3 vulnerabilidades com PoC pública reforçam a necessidade de monitoramento contínuo, especialmente em ambientes expostos.

CVE-2017-11481Kibana versions prior to 6.0.1 and 5.6.5 had a cross-site scripting (XSS) vulnerability via URL fields that could allow an attacker to obtaiEPSS 0.8%CVE-2018-3820Kibana versions after 6.1.0 and before 6.1.3 had a cross-site scripting (XSS) vulnerability in labs visualizations that could allow an attacEPSS 0.8%CVE-2018-3819The fix in Kibana for ESA-2017-23 was incomplete. With X-Pack security enabled, Kibana versions before 6.1.3 and 5.6.7 have an open redirectEPSS 0.8%CVE-2017-8449X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules used a mix of grantEPSS 0.8%CVE-2022-23713A cross-site-scripting (XSS) vulnerability was discovered in the Vega Charts Kibana integration which could allow arbitrary JavaScript to beEPSS 0.8%CVE-2015-9056Kibana versions prior to 4.1.3 and 4.2.1 are vulnerable to a XSS attack.EPSS 0.8%CVE-2022-23715A flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwords and ElasticsearcEPSS 0.8%CVE-2023-31422CRITICALKibana Insertion of Sensitive Information into Log FileEPSS 0.8%CVE-2020-7015Kibana versions before 6.8.9 and 7.7.0 contains a stored XSS flaw in the TSVB visualization. An attacker who is able to edit or create a TSVEPSS 0.8%CVE-2022-23710A cross-site-scripting (XSS) vulnerability was discovered in the Data Preview Pane (previously known as Index Pattern Preview Pane) which coEPSS 0.8%CVE-2017-11482The Kibana fix for CVE-2017-8451 was found to be incomplete. With X-Pack installed, Kibana versions before 6.0.1 and 5.6.5 have an open rediEPSS 0.7%CVE-2017-8441Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to index aliases. This bug EPSS 0.7%CVE-2021-37938It was discovered that on Windows operating systems specifically, Kibana was not validating a user supplied path, which would load .pbf fileEPSS 0.7%CVE-2021-37937MEDIUMElasticsearch privilege escalationEPSS 0.7%CVE-2019-7621Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attackeEPSS 0.7%CVE-2021-22151LOWKibana path traversal issueEPSS 0.7%CVE-2017-8446The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonaEPSS 0.7%CVE-2018-3826In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameEPSS 0.7%CVE-2023-46675HIGHKibana Insertion of Sensitive Information into Log FileEPSS 0.7%CVE-2024-23449MEDIUMElasticsearch Uncaught ExceptionEPSS 0.7%