Elasticsearch Winlogbeat是荷兰Elasticsearch公司的一款用于将Windows事件日志发送到Elasticsearch的开源工具。 Elasticsearch Winlogbeat 5.6.16之前版本和6.6.2之前版本中存在安全漏洞。攻击者可通过注入字符利用该漏洞造成Winlogbeat无法对事件进行记录。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2019-7608 | Elasticsearch Kibana 跨站脚本漏洞 | |
| CVE-2019-7610 | Elasticsearch Kibana 命令注入漏洞 | |
| CVE-2019-7611 | Elasticsearch 安全漏洞 | |
| CVE-2019-7612 | Elasticsearch Logstash 日志信息泄露漏洞 | |
| CVE-2019-7609 | Elasticsearch Kibana 代码注入漏洞 |
No comments yet