All 43 CVE vulnerabilities found in Elasticsearch, with AI-generated Chinese analysis, references, and POCs.
This page aggregates Common Weakness Enumerations (CWEs) specifically related to the Elasticsearch product developed by Elastic. It serves as a centralized repository for analyzing security flaws, configuration errors, and implementation defects that affect the distributed search and analytics engine. The content herein compiles vulnerability data sourced from vendor advisories, independent security disclosures, and public databases, covering a historical timeline that extends back to the earliest tracked releases of the software. Readers can utilize this resource to track Elastic’s security advisories over time, gaining insight into how the vendor addresses critical issues. Furthermore, users can understand specific weakness classes by examining how abstract CWE categories manifest in real-world scenarios within Elasticsearch. The page also allows for a comprehensive look up of a product’s vulnerability history, enabling developers and security professionals to assess the long-term security posture of the platform. By reviewing past incidents and their resolutions, stakeholders can better evaluate the impact of known flaws on their deployments and prioritize remediation efforts effectively. This aggregated view helps in correlating multiple CVE entries to identify patterns in vulnerability types, such as authentication bypasses or remote code execution risks, providing a holistic perspective on the security landscape surrounding Elasticsearch without focusing on isolated events.
Vendor: Elastic
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2021-22132 | Elastic 资源管理错误漏洞 CWE-522 | 4.3 | - | 2021-01-14 |
| CVE-2020-7020 | Elasticsearch 安全漏洞 CWE-270 | 3.1 | - | 2020-10-22 |
| CVE-2020-7019 | Elasticsearch 安全漏洞 CWE-270 | 6.5 | - | 2020-08-18 |
| CVE-2020-7014 | Elasticsearch 安全漏洞 CWE-266 | 8.8 | - | 2020-06-03 |
| CVE-2020-7009 | Elasticsearch 安全漏洞 CWE-266 | 8.8 | - | 2020-03-31 |
| CVE-2019-7619 | Elasticsearch 加密问题漏洞 CWE-200 | 5.3 | - | 2019-10-30 |
| CVE-2019-7614 | Elasticsearch 竞争条件问题漏洞 CWE-362 | 5.9 | - | 2019-07-30 |
| CVE-2019-7611 | Elasticsearch 安全漏洞 CWE-284 | 8.1 | - | 2019-03-25 |
| CVE-2018-17244 | Elasticsearch Security 安全漏洞 CWE-362 | 7.5 | - | 2018-12-20 |
| CVE-2018-17247 | Elasticsearch Security 跨站脚本漏洞 CWE-611 | 5.9 | - | 2018-12-20 |
| CVE-2018-3831 | Elasticsearch Alerting and Monitoring 信息泄露漏洞 CWE-200 | 8.1 | - | 2018-09-19 |
| CVE-2018-3827 | Elasticsearch repository-azure插件信任管理问题漏洞 CWE-532 | 8.1 | - | 2018-09-19 |
| CVE-2018-3826 | Elasticsearch 安全漏洞 CWE-200 | 5.3 | - | 2018-09-19 |
All 43 known CVE vulnerabilities affecting Elasticsearch with full Chinese analysis, references, and POCs where available.