Elastic Agent是荷兰Elastic公司的一个单一代理。可从每台主机收集日志、指标、跟踪、可用性、安全性和其他数据。 Elastic Agent存在安全漏洞,该漏洞源于未控制从不受信控制区域引入功能,可能导致本地用户执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Elastic | Elastic Agent | 7.0.0 ~ 7.17.24 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-52979 | 6.5 MEDIUM | Elasticsearch Uncontrolled Resource Consumption vulnerability |
| CVE-2023-46669 | 6.2 MEDIUM | Elastic Agent / Elastic Endpoint Security local API key disclosure |
| CVE-2024-11994 | 5.7 MEDIUM | APM Server Insertion of Sensitive Information into Log File |
| CVE-2024-11390 | 5.4 MEDIUM | Kibana Unrestricted Upload of File with Dangerous Type Can Lead to XSS |
| CVE-2025-25016 | 4.3 MEDIUM | Kibana Unrestricted Upload of File |
No comments yet