Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Elastic — Vulnerabilities & Security Advisories 309

Browse all 309 CVE security advisories affecting Elastic. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Elastic operates as a search and analytics engine, primarily powering the ELK Stack for log management and data visualization. With 223 recorded Common Vulnerabilities and Exposures, the platform has historically been susceptible to critical flaws, including remote code execution, cross-site scripting, and privilege escalation vulnerabilities. These issues often stem from improper input validation and authentication bypasses within its Java-based architecture. Notable incidents involve unauthorized access to sensitive data through exposed APIs, highlighting risks associated with default configurations. The sheer volume of CVEs suggests persistent challenges in securing complex distributed systems. While the software remains a cornerstone for enterprise search, its extensive attack surface requires rigorous patching and strict access controls to mitigate the high probability of exploitation by threat actors targeting its widespread deployment infrastructure.

CVE ID Title CVSS Severity Published
CVE-2023-46671 Kibana Insertion of Sensitive Information into Log File — Kibana CWE-532 8.0 High 2023-12-13
CVE-2023-6687 Elastic Agent Insertion of Sensitive Information into Log File — Elastic Agent CWE-532 6.8 Medium 2023-12-12
CVE-2023-49922 Beats Insertion of Sensitive Information into Log File — Beats CWE-532 6.8 Medium 2023-12-12
CVE-2023-49923 Enterprise Search Insertion of Sensitive Information into Log File — Enterprise Search CWE-532 6.8 Medium 2023-12-12
CVE-2023-46674 Elasticsearch-hadoop Unsafe Deserialization — Elasticsearch-Hadoop CWE-502 6.0 Medium 2023-12-05
CVE-2023-46673 Elasticsearch 安全漏洞 — Elasticsearch CWE-755 6.5 Medium 2023-11-22
CVE-2021-37937 Elasticsearch privilege escalation — Elasticsearch CWE-269 5.9 Medium 2023-11-22
CVE-2021-37942 APM Java Agent Local Privilege Escalation — Elastic APM Java Agent CWE-269 7.0 High 2023-11-22
CVE-2021-22143 Elastic APM .NET Agent information disclosure — Elastic APM .NET Agent CWE-200 2.1 Low 2023-11-22
CVE-2021-22142 Kibana Reporting vulnerabilities — Kibana CWE-1104 6.6 Medium 2023-11-22
CVE-2021-22151 Kibana path traversal issue — Kibana CWE-22 3.1 Low 2023-11-22
CVE-2021-22150 Kibana code execution issue — Kibana CWE-94 6.6 Medium 2023-11-22
CVE-2023-46672 Logstash Insertion of Sensitive Information into Log File — Logstash CWE-532 8.4 High 2023-11-15
CVE-2023-31416 Elastic Cloud on Kubernetes (ECK) secret token configuration issue — Elastic Cloud on Kubernetes CWE-200 5.3 Medium 2023-10-26
CVE-2023-31417 Elasticsearch Insertion of sensitive information in audit logs — Elasticsearch CWE-532 4.1 Medium 2023-10-26
CVE-2023-31418 Elasticsearch uncontrolled resource consumption — Elasticsearch CWE-400 7.5 High 2023-10-26
CVE-2023-31419 Elasticsearch StackOverflow vulnerability — Elasticsearch CWE-121 6.5 Medium 2023-10-26
CVE-2023-46666 Elastic Sharepoint Online Python Connector Improper Access Control — Elastic Sharepoint Online Python Connector CWE-284 5.3 Medium 2023-10-26
CVE-2023-31421 Beats, Elastic Agent, APM Server, and Fleet Server Improper Certificate Validation issue — Beats CWE-295 5.9 Medium 2023-10-26
CVE-2023-31422 Kibana Insertion of Sensitive Information into Log File — Kibana CWE-532 9.0 Critical 2023-10-26
CVE-2023-46667 Fleet Server Insertion of Sensitive Information into Log File — Fleet Server CWE-532 8.1 High 2023-10-26
CVE-2023-46668 Elastic Endpoint Insertion of Sensitive Information into Log File — Endpoint CWE-532 4.6 Medium 2023-10-25
CVE-2023-31415 Elastic Kibana 代码注入漏洞 — Kibana CWE-94 9.9 - 2023-05-04
CVE-2023-31414 Elastic Kibana 代码注入漏洞 — Kibana CWE-94 9.1 - 2023-05-04
CVE-2023-31413 Elastic Filebeat 日志信息泄露漏洞 — Filebeat CWE-200 7.5 - 2023-05-04
CVE-2022-38779 Elastic Kibana 输入验证错误漏洞 — kibana CWE-601 6.1 - 2023-02-21
CVE-2022-38777 Elastic Endpoint Security 安全漏洞 — Elastic Endpoint Security CWE-269 7.8 - 2023-02-08
CVE-2022-38778 Kibana 输入验证错误漏洞 — kibana CWE-20 6.5 - 2023-02-08
CVE-2022-38774 Elastic Endpoint Security 安全漏洞 — Elastic Endpoint Security and Elastic Endgame Security CWE-269 7.8 - 2023-01-24
CVE-2022-38775 Elastic Endpoint Security 安全漏洞 — Elastic Endpoint Security CWE-269 7.8 - 2023-01-24

This page lists every published CVE security advisory associated with Elastic. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.