Elastic是荷兰Elastic公司的一套基于Lucene构建的开源分布式RESTful搜索引擎。该产品主要应用于云计算,并支持通过HTTP使用JSON进行数据索引。 Elastic Agent和 Beats 7.0.0 到 7.17.16、8.0.0 到8.11.2版本存在安全漏洞,该漏洞源于将原始事件提取到 Elasticsearch 失败并显示除 409 或 429 之外的任何 4xx HTTP 状态码时,Beats 和 Elastic Agent 会在自己的日志中以 WARN 或 ERROR 级
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-49923 | 6.8 MEDIUM | Enterprise Search Insertion of Sensitive Information into Log File |
| CVE-2023-6687 | 6.8 MEDIUM | Elastic Agent Insertion of Sensitive Information into Log File |
No comments yet