Vulnerabilities
Vulnerable Software
Elastic:  Security Vulnerabilities
A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.
CVSS Score
9.1
EPSS Score
0.009
Published
2025-05-06
Unrestricted file upload in Kibana allows an authenticated attacker to compromise software integrity by uploading a crafted malicious file due to insufficient server-side validation.
CVSS Score
4.3
EPSS Score
0.0
Published
2025-05-01
Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd, allows local attackers to execute arbitrary code via parameter injection. An attacker requires local access and the ability to modify osqueryd configurations.
CVSS Score
4.4
EPSS Score
0.0
Published
2025-05-01
Uncontrolled Resource Consumption in Elasticsearch while evaluating specifically crafted search templates with Mustache functions can lead to Denial of Service by causing the Elasticsearch node to crash.
CVSS Score
6.5
EPSS Score
0.002
Published
2025-05-01
Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s browser (XSS) via crafted HTML and JavaScript files. The attacker must have access to the Synthetics app AND/OR have access to write to the synthetics indices.
CVSS Score
5.4
EPSS Score
0.0
Published
2025-05-01
Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead to loss of confidentiality and impersonation of Endpoint to the Elastic Stack. This issue was identified by Elastic engineers and Elastic has no indication that it is known or has been exploited by malicious actors.
CVSS Score
6.2
EPSS Score
0.0
Published
2025-05-01
Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined with path traversal.
CVSS Score
8.7
EPSS Score
0.005
Published
2025-04-08
An issue was discovered in Elasticsearch, where a large recursion using the Well-KnownText formatted string with nested GeometryCollection objects could cause a stackoverflow.
CVSS Score
4.9
EPSS Score
0.003
Published
2025-04-08
An issue has been identified where a specially crafted request sent to an Observability API could cause the kibana server to crash. A successful attack requires a malicious user to have read permissions for Observability assigned to them.
CVSS Score
6.5
EPSS Score
0.001
Published
2025-04-08
A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the PatternBank class could cause the Elasticsearch node to crash. A successful attack requires a malicious user to have read_pipeline Elasticsearch cluster privilege assigned to them.
CVSS Score
6.5
EPSS Score
0.002
Published
2025-04-08


Contact Us

Shodan ® - All rights reserved