Vulnerabilidades em Elastic

352 resultados
Análise Vexday

Com 233 CVEs catalogadas, o ecossistema Elastic apresenta taxa de exploração ativa em linha com a média geral do catálogo, o que não elimina pontos de atenção relevantes. O CVE-2019-7609, única entrada confirmada no CISA KEV, carrega EPSS de 0,9534 — valor extremamente elevado que indica alta probabilidade de exploração ativa e deve ser prioridade absoluta para equipes que ainda não aplicaram a correção correspondente. O tipo de falha mais frequente, CWE-79 (Cross-Site Scripting), sugere que controles de sanitização de entrada e saída merecem atenção sistemática no ciclo de desenvolvimento e hardening das implantações. As 17 CVEs surgidas nos últimos 90 dias e a existência de 3 vulnerabilidades com PoC pública reforçam a necessidade de monitoramento contínuo, especialmente em ambientes expostos.

CVE-2022-23716MEDIUMA flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in dEPSS 0.6%CVE-2024-52981MEDIUMAn issue was discovered in Elasticsearch, where a large recursion using the Well-KnownText formatted string with nested GeometryCollection oEPSS 0.6%CVE-2024-37283MEDIUMElastic Agent Insertion of Sensitive Information into Log FileEPSS 0.6%CVE-2022-23709A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A user with this privilegEPSS 0.6%CVE-2023-46667HIGHFleet Server Insertion of Sensitive Information into Log FileEPSS 0.5%CVE-2026-33466HIGHImproper Limitation of a Pathname to a Restricted Directory in Logstash Leading to Arbitrary File WriteEPSS 0.5%CVE-2024-12556HIGHKibana Prototype Pollution can lead to code injectionEPSS 0.5%CVE-2024-52980MEDIUMElasticsearch Uncontrolled Resource Consumption vulnerabilityEPSS 0.5%CVE-2022-23707An XSS vulnerability was found in Kibana index patterns. Using this vulnerability, an authenticated user with permissions to create index paEPSS 0.5%CVE-2021-22133The Elastic APM agent for Go versions before 1.11.0 can leak sensitive HTTP header information when logging the details during an applicatioEPSS 0.5%CVE-2022-38779An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciouslyEPSS 0.5%CVE-2024-23446MEDIUMKibana Broken Access Control issueEPSS 0.5%CVE-2026-56149MEDIUMAllocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of ServiceEPSS 0.5%CVE-2024-37286MEDIUMAPM Server Insertion of Sensitive Information into Log FileEPSS 0.5%CVE-2024-23451MEDIUMElasticsearch Incorrect Authorization in the Remote Cluster Security API key based security modelEPSS 0.5%CVE-2021-37936MEDIUMIt was discovered that Kibana was not sanitizing document fields containing HTML snippets. Using this vulnerability, an attacker with the abEPSS 0.5%CVE-2026-0532HIGHExternal Control of File Name or Path and Server-Side Request Forgery (SSRF) in Kibana Google Gemini ConnectorEPSS 0.5%CVE-2026-0531MEDIUMAllocation of Resources Without Limits or Throttling in Kibana FleetEPSS 0.5%CVE-2026-56150MEDIUMAllocation of Resources Without Limits or Throttling in Fleet Server Leading to Denial of ServiceEPSS 0.5%CVE-2026-63260MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of ServiceEPSS 0.5%