Search CVE reports


Toggle filters

41 – 48 of 48 results


CVE-2018-3827

Medium priority
Not affected

A sensitive data disclosure flaw was found in the Elasticsearch repository-azure (formerly elasticsearch-cloud-azure) plugin. When the repository-azure plugin is set to log at TRACE level Azure credentials can be inadvertently logged.

1 affected package

elasticsearch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
elasticsearch Not in release
Show less packages

CVE-2018-3826

Medium priority
Not affected

In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameters are set using the _snapshot API they can be exposed as plain text by users able to...

1 affected package

elasticsearch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
elasticsearch Not in release
Show less packages

CVE-2015-5377

Medium priority
Ignored

Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerability

1 affected package

elasticsearch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
elasticsearch Not in release
Show less packages

CVE-2015-4165

Medium priority
Ignored

The snapshot API in Elasticsearch before 1.6.0 when another application exists on the system that can read Lucene files and execute code from them, is accessible by the attacker, and the Java VM on which Elasticsearch is running...

1 affected package

elasticsearch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
elasticsearch Not in release
Show less packages

CVE-2015-5531

Low priority
Ignored

Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unspecified vectors related to snapshot API calls.

1 affected package

elasticsearch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
elasticsearch Not in release
Show less packages

CVE-2015-3337

Medium priority
Fixed

Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors.

1 affected package

elasticsearch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
elasticsearch
Show less packages

CVE-2015-1427

Medium priority
Ignored

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

1 affected package

elasticsearch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
elasticsearch Not in release
Show less packages

CVE-2014-6439

Medium priority
Needs evaluation

Cross-site scripting (XSS) vulnerability in the CORS functionality in Elasticsearch before 1.4.0.Beta1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1 affected package

elasticsearch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
elasticsearch Not in release Not in release
Show less packages