Elasticsearch是荷兰Elasticsearch公司的一套基于Lucene构建的开源分布式RESTful搜索引擎。该产品主要应用于云计算,并支持通过HTTP使用JSON进行数据索引。Security是其中的一个数据保护组件。 Elasticsearch Security 5.6.15之前版本和6.6.1之前版本中存在安全漏洞。攻击者可利用该漏洞绕过限制,进而提升权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Elastic | Elasticsearch | before 5.6.15 and 6.6.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2019-7608 | Elasticsearch Kibana 跨站脚本漏洞 | |
| CVE-2019-7610 | Elasticsearch Kibana 命令注入漏洞 | |
| CVE-2019-7612 | Elasticsearch Logstash 日志信息泄露漏洞 | |
| CVE-2019-7613 | Elasticsearch Winlogbeat 输入验证错误漏洞 | |
| CVE-2019-7609 | Elasticsearch Kibana 代码注入漏洞 |
No comments yet