Vulnerabilidades em Elastic

352 resultados
Análise Vexday

Com 233 CVEs catalogadas, o ecossistema Elastic apresenta taxa de exploração ativa em linha com a média geral do catálogo, o que não elimina pontos de atenção relevantes. O CVE-2019-7609, única entrada confirmada no CISA KEV, carrega EPSS de 0,9534 — valor extremamente elevado que indica alta probabilidade de exploração ativa e deve ser prioridade absoluta para equipes que ainda não aplicaram a correção correspondente. O tipo de falha mais frequente, CWE-79 (Cross-Site Scripting), sugere que controles de sanitização de entrada e saída merecem atenção sistemática no ciclo de desenvolvimento e hardening das implantações. As 17 CVEs surgidas nos últimos 90 dias e a existência de 3 vulnerabilidades com PoC pública reforçam a necessidade de monitoramento contínuo, especialmente em ambientes expostos.

CVE-2024-23448MEDIUMAPM Server Insertion of Sensitive Information into Log FileEPSS 0.7%CVE-2023-49922MEDIUMBeats Insertion of Sensitive Information into Log FileEPSS 0.7%CVE-2025-37729CRITICALElastic Cloud Enterprise (ECE) Improper Neutralization of Special Elements Used in a Template EngineEPSS 0.7%CVE-2023-46671HIGHKibana Insertion of Sensitive Information into Log FileEPSS 0.7%CVE-2018-3825In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 a default master encryption key is used in the process of granting ZooKeeper accesEPSS 0.7%CVE-2018-3823X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. Users with manage_ml permissions couEPSS 0.6%CVE-2019-7615A TLS certificate validation flaw was found in Elastic APM agent for Ruby versions before 2.9.0. When specifying a trusted server CA certifiEPSS 0.6%CVE-2026-72649HIGHDeserialization of Untrusted Data in Elasticsearch Leading to Remote Code ExecutionEPSS 0.6%CVE-2024-52979MEDIUMElasticsearch Uncontrolled Resource Consumption vulnerabilityEPSS 0.6%CVE-2024-43709MEDIUMElasticsearch allocation of resources without limits or throttling leads to crashEPSS 0.6%CVE-2024-37280MEDIUMElasticsearch StackOverflow vulnerabilityEPSS 0.6%CVE-2017-8447An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index' permissions on an iEPSS 0.6%CVE-2021-22143LOWElastic APM .NET Agent information disclosureEPSS 0.6%CVE-2024-37282HIGHIt was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subsEPSS 0.6%CVE-2023-31414HIGHKibana versions 8.0.0 through 8.7.0 contain an arbitrary code execution flaw. An attacker with write access to Kibana yaml or env configuratEPSS 0.6%CVE-2018-3828Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exceptiEPSS 0.6%CVE-2023-49923MEDIUMEnterprise Search Insertion of Sensitive Information into Log FileEPSS 0.6%CVE-2023-6687MEDIUMElastic Agent Insertion of Sensitive Information into Log FileEPSS 0.6%CVE-2017-8444The client-forwarder in Elastic Cloud Enterprise versions prior to 1.0.2 do not properly encrypt traffic to ZooKeeper. If an attacker is ablEPSS 0.6%CVE-2021-22141MEDIUMAn open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously crafted URL, it could EPSS 0.6%