Elasticsearch是一个基于Lucene库的搜索引擎。 Elasticsearch 存在安全漏洞,该漏洞源于攻击者可利用该漏洞可以通过Elasticsearch的Fleet-server服务API密钥绕过限制,以升级他的特权。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Elastic | Elasticsearch | 7.13.0 ~ 7.14.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-37942 | 7.0 HIGH | APM Java Agent Local Privilege Escalation |
| CVE-2021-22142 | 6.6 MEDIUM | Kibana Reporting vulnerabilities |
| CVE-2021-22150 | 6.6 MEDIUM | Kibana code execution issue |
| CVE-2023-46673 | 6.5 MEDIUM | Elasticsearch 安全漏洞 |
| CVE-2021-22151 | 3.1 LOW | Kibana path traversal issue |
| CVE-2021-22143 | 2.1 LOW | Elastic APM .NET Agent information disclosure |
No comments yet