Elastic Enterprise Search是荷兰Elastic公司的一款企业搜索工具。 Elastic Enterprise Search 7.0.0 到 7.17.16、8.0.0 到8.11.2版本存在安全漏洞,该漏洞源于App Search 的Documents API 在 INFO 日志级别记录了索引文档的原始内容,这可能会导致在 App Search 日志中插入敏感或私人信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Elastic | Enterprise Search | 7.0.0 ~ 7.17.16 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-49922 | 6.8 MEDIUM | Beats Insertion of Sensitive Information into Log File |
| CVE-2023-6687 | 6.8 MEDIUM | Elastic Agent Insertion of Sensitive Information into Log File |
No comments yet