MidnightBSD

Advisories for elasticsearch

CVE-2014-6439 MEDIUM

Cross-site scripting (XSS) vulnerability in the CORS functionality in Elasticsearch before 1.4.0.Beta1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
elasticsearch elasticsearch *
CVE-2015-3337 MEDIUM

Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
elasticsearch elasticsearch *
elasticsearch elasticsearch 1.5.1
elasticsearch elasticsearch 1.5.0
CVE-2015-4165 MEDIUM

The snapshot API in Elasticsearch before 1.6.0 when another application exists on the system that can read Lucene files and execute code from them, is accessible by the attacker, and the Java VM on which Elasticsearch is running can write to a location that the other application can read and execute from, allows remote authenticated users to write to and create arbitrary snapshot metadata files, and potentially execute arbitrary code.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
elasticsearch elasticsearch 1.5.2
CVE-2015-5378 MEDIUM

Logstash 1.5.x before 1.5.3 and 1.4.x before 1.4.4 allows remote attackers to read communications between Logstash Forwarder agent and Logstash server.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
elastic logstash 1.4.0
elasticsearch logstash 1.4.3
elasticsearch logstash 1.5.1
elasticsearch logstash 1.5.2
elasticsearch logstash 1.5.0
elastic logstash 1.4.2
elastic logstash 1.4.1
CVE-2015-5531 MEDIUM

Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unspecified vectors related to snapshot API calls.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
elasticsearch elasticsearch *
CVE-2015-5619 MEDIUM

Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might allow attackers to obtain sensitive information via a man-in-the-middle attack.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-295,

Products Affected

Vendor Product Version
elastic logstash 1.4.0
elasticsearch logstash 1.4.3
elasticsearch logstash 1.5.1
elasticsearch logstash 1.5.2
elasticsearch logstash 1.4.4
elasticsearch logstash 1.5.0
elastic logstash 1.4.2
elasticsearch logstash 1.5.3
elastic logstash 1.4.1
CVE-2016-10362 MEDIUM

Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file HTTP basic auth credentials.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-532,CWE-200,

Products Affected

Vendor Product Version
elasticsearch output_plugin *
CVE-2017-11479 MEDIUM

Kibana versions prior to 5.6.1 had a cross-site scripting (XSS) vulnerability in Timelion that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
elastic kibana 5.4.2
elastic kibana 5.1.1
elastic kibana 5.5.0
elastic kibana 5.3.0
elastic kibana 5.0.0
elastic kibana 5.4.3
elastic kibana 5.5.2
elastic kibana 5.3.1
elastic kibana 5.0.1
elastic kibana 5.3.2
elastic kibana 5.5.3
elasticsearch kibana 5.1.0
elastic kibana 5.2.1
elastic kibana 5.6.0
elastic kibana 5.4.0
elastic kibana 5.0.2
elastic kibana 5.5.1
elastic kibana 5.2.2
elastic kibana 5.1.2
elastic kibana 5.4.1
elastic kibana 5.3.3
elastic kibana 5.2.0
CVE-2017-11480 MEDIUM

Packetbeat versions prior to 5.6.4 are affected by a denial of service flaw in the PostgreSQL protocol handler. If Packetbeat is listening for PostgreSQL traffic and a user is able to send arbitrary network traffic to the monitored port, the attacker could prevent Packetbeat from properly logging other PostgreSQL traffic.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-404,NVD-CWE-noinfo,

Products Affected

Vendor Product Version
elasticsearch packetbeat *
CVE-2017-14730 HIGH

The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls for user-writable directory trees, which allows local users to gain privileges by leveraging access to a $LS_USER account for creation of a hard link.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-732,

Products Affected

Vendor Product Version
elasticsearch logstash 5.6.0
elasticsearch logstash 5.0.1
elasticsearch logstash 5.5.2
elasticsearch logstash 5.4.3
elasticsearch logstash 5.3.2
elasticsearch logstash 5.2.0
elasticsearch logstash 5.5.1
elasticsearch logstash 5.0.0
elasticsearch logstash 5.2.1
elasticsearch logstash 5.0.2
elasticsearch logstash 5.3.1
elasticsearch logstash 5.1.2
elasticsearch logstash 5.3.0
elasticsearch logstash 5.4.1
elasticsearch logstash 5.4.2
elasticsearch logstash 5.5.0
elasticsearch logstash 5.1.1
CVE-2017-8444 MEDIUM

The client-forwarder in Elastic Cloud Enterprise versions prior to 1.0.2 do not properly encrypt traffic to ZooKeeper. If an attacker is able to man in the middle (MITM) the traffic between the client-forwarder and ZooKeeper they could potentially obtain sensitive data.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-319,NVD-CWE-noinfo,

Products Affected

Vendor Product Version
elasticsearch cloud_enterprise 1.0.1
elasticsearch cloud_enterprise 1.0.0
CVE-2017-8446 MEDIUM

The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vulnerability. A user with the reporting_user role could execute a report with the permissions of another reporting user, possibly gaining access to sensitive data.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-522,CWE-269,

Products Affected

Vendor Product Version
elasticsearch x-pack *
elasticsearch x-pack_reporting *