Elasticsearch是一个基于Lucene库的搜索引擎。 Elasticsearch 存在安全漏洞,该漏洞源于未经身份验证的用户可以通过发送适量的格式错误的 HTTP 请求来强制 Elasticsearch 节点退出并出现 OutOfMemory 错误。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Elastic | Elasticsearch | 7.17.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-31422 | 9.0 CRITICAL | Kibana Insertion of Sensitive Information into Log File |
| CVE-2023-46667 | 8.1 HIGH | Fleet Server Insertion of Sensitive Information into Log File |
| CVE-2023-31419 | 6.5 MEDIUM | Elasticsearch StackOverflow vulnerability |
| CVE-2023-31421 | 5.9 MEDIUM | Beats, Elastic Agent, APM Server, and Fleet Server Improper Certificate Validation issue |
| CVE-2023-46666 | 5.3 MEDIUM | Elastic Sharepoint Online Python Connector Improper Access Control |
| CVE-2023-31416 | 5.3 MEDIUM | Elastic Cloud on Kubernetes (ECK) secret token configuration issue |
| CVE-2023-31417 | 4.1 MEDIUM | Elasticsearch Insertion of sensitive information in audit logs |
No comments yet