Refine your search
11 vulnerabilities found for Apm Server by Elastic
CVE-2026-78594 (GCVE-0-2026-78594)
Vulnerability from cvelistv5
- CWE-409 - Improper Handling of Highly Compressed Data (Data Amplification)
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Elastic | Apm Server |
Version: 8.0.0 ≤ 8.19.19 Version: 9.0.0 ≤ 9.4.4 Version: 9.5.0 ≤ |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-78594",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-02T15:44:44.239209Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T15:58:12.264Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Apm Server",
"vendor": "Elastic",
"versions": [
{
"lessThanOrEqual": "8.19.19",
"status": "affected",
"version": "8.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.4",
"status": "affected",
"version": "9.0.0",
"versionType": "semver"
},
{
"status": "affected",
"version": "9.5.0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eImproper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to a persistent denial of service via Excessive Allocation (CAPEC-130). An authenticated user with write access to source map content could store specially crafted, highly compressed content that exhausts the memory available to APM Server when it is later processed, terminating the process. The condition recurs on every restart until the stored content is removed.\u003c/p\u003e"
}
],
"value": "Improper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to a persistent denial of service via Excessive Allocation (CAPEC-130). An authenticated user with write access to source map content could store specially crafted, highly compressed content that exhausts the memory available to APM Server when it is later processed, terminating the process. The condition recurs on every restart until the stored content is removed."
}
],
"impacts": [
{
"capecId": "CAPEC-130",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-130 Excessive Allocation"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-409",
"description": "CWE-409 Improper Handling of Highly Compressed Data (Data Amplification)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T14:43:13.303Z",
"orgId": "271b6943-45a9-4f3a-ab4e-976f3fa05b5a",
"shortName": "elastic"
},
"references": [
{
"url": "https://discuss.elastic.co/t/apm-server-8-19-20-9-4-5-9-5-1-security-update-esa-2026-152/390110"
}
],
"source": {
"discovery": "Elastic"
},
"title": "Improper Handling of Highly Compressed Data in APM Server Leading to Persistent Denial of Service",
"x_generator": {
"engine": "Elastic CVE Publisher 1.0.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "271b6943-45a9-4f3a-ab4e-976f3fa05b5a",
"assignerShortName": "elastic",
"cveId": "CVE-2026-78594",
"datePublished": "2026-09-02T14:43:13.303Z",
"dateReserved": "2026-08-24T21:13:51.299Z",
"dateUpdated": "2026-09-02T15:58:12.264Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-0712 (GCVE-0-2025-0712)
Vulnerability from cvelistv5
- CWE-427 - Uncontrolled Search Path Element
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Elastic | APM Server |
Version: 8.16 ≤ 8.16.2 Version: 8.17 ≤ 8.17.0 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-0712",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-07-30T14:05:34.662092Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-07-30T14:06:16.977Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "APM Server",
"vendor": "Elastic",
"versions": [
{
"lessThanOrEqual": "8.16.2",
"status": "affected",
"version": "8.16",
"versionType": "semver"
},
{
"lessThanOrEqual": "8.17.0",
"status": "affected",
"version": "8.17",
"versionType": "semver"
}
]
}
],
"datePublic": "2025-07-30T00:05:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cb\u003e\u003cspan style=\"background-color: transparent;\"\u003eAn uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions. The vulnerability arises from improper handling of directory permissions. An attacker with local access may exploit this flaw to move and delete arbitrary files, potentially gaining SYSTEM privileges.\u003c/span\u003e\u003c/b\u003e\u003cbr\u003e"
}
],
"value": "An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions. The vulnerability arises from improper handling of directory permissions. An attacker with local access may exploit this flaw to move and delete arbitrary files, potentially gaining SYSTEM privileges."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-427",
"description": "CWE-427 Uncontrolled Search Path Element",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-07-30T00:12:43.639Z",
"orgId": "271b6943-45a9-4f3a-ab4e-976f3fa05b5a",
"shortName": "elastic"
},
"references": [
{
"url": "https://discuss.elastic.co/t/beats-windows-installer-9-1-0-security-update-esa-2025-12/380558"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "APM Server Uncontrolled Search Path Element can lead to Local Privilege Escalation (LPE) when using the Windows Installer",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "271b6943-45a9-4f3a-ab4e-976f3fa05b5a",
"assignerShortName": "elastic",
"cveId": "CVE-2025-0712",
"datePublished": "2025-07-30T00:12:43.639Z",
"dateReserved": "2025-01-24T11:35:22.838Z",
"dateUpdated": "2025-07-30T14:06:16.977Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2024-11994 (GCVE-0-2024-11994)
Vulnerability from cvelistv5
- CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Elastic | APM Server |
Version: 8.0.0 ≤ |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-11994",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-05-01T14:30:02.890444Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-05-01T15:32:54.220Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "APM Server",
"repo": "https://github.com/elastic/apm-server",
"vendor": "Elastic",
"versions": [
{
"lessThan": "8.16.1",
"status": "affected",
"version": "8.0.0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eAPM server logs could contain parts of the document body from a partially failed bulk index request. Depending on the nature of the document, this could disclose sensitive information in APM Server error logs.\u003c/p\u003e"
}
],
"value": "APM server logs could contain parts of the document body from a partially failed bulk index request. Depending on the nature of the document, this could disclose sensitive information in APM Server error logs."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.7,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-200",
"description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-05-01T13:06:54.194Z",
"orgId": "271b6943-45a9-4f3a-ab4e-976f3fa05b5a",
"shortName": "elastic"
},
"references": [
{
"url": "https://discuss.elastic.co/t/apm-server-8-16-1-security-update-esa-2024-41/377710"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "APM Server Insertion of Sensitive Information into Log File",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "271b6943-45a9-4f3a-ab4e-976f3fa05b5a",
"assignerShortName": "elastic",
"cveId": "CVE-2024-11994",
"datePublished": "2025-05-01T13:06:54.194Z",
"dateReserved": "2024-11-29T15:12:45.792Z",
"dateUpdated": "2025-05-01T15:32:54.220Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2024-37286 (GCVE-0-2024-37286)
Vulnerability from cvelistv5
- CWE-532 - Insertion of Sensitive Information into Log File
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Elastic | APM Server |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-37286",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-08-05T15:49:35.536482Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-09-03T15:36:33.784Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "APM Server",
"vendor": "Elastic",
"versions": [
{
"status": "unaffected",
"version": "8.14.0",
"versionType": "semver"
}
]
}
],
"datePublic": "2024-08-03T15:07:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "APM server logs contain document body from a partially failed bulk index request. For example, in case of unavailable_shards_exception for a specific document, since the ES response line contains the document body, and that APM server logs the ES response line on error, the document is effectively logged."
}
],
"value": "APM server logs contain document body from a partially failed bulk index request. For example, in case of unavailable_shards_exception for a specific document, since the ES response line contains the document body, and that APM server logs the ES response line on error, the document is effectively logged."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.7,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-532",
"description": "CWE-532: Insertion of Sensitive Information into Log File",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-08-03T15:16:22.700Z",
"orgId": "271b6943-45a9-4f3a-ab4e-976f3fa05b5a",
"shortName": "elastic"
},
"references": [
{
"url": "https://discuss.elastic.co/t/apm-server-8-14-0-security-update-esa-2024-19/364289"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "APM Server Insertion of Sensitive Information into Log File",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "271b6943-45a9-4f3a-ab4e-976f3fa05b5a",
"assignerShortName": "elastic",
"cveId": "CVE-2024-37286",
"datePublished": "2024-08-03T15:16:22.700Z",
"dateReserved": "2024-06-05T14:21:14.942Z",
"dateUpdated": "2024-09-03T15:36:33.784Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2024-23448 (GCVE-0-2024-23448)
Vulnerability from cvelistv5
- CWE-532 - Insertion of Sensitive Information into Log File
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Elastic | APM Server |
Version: 8.12 ≤ |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-23448",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-02-08T17:06:16.249539Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-07-05T17:20:45.143Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-01T23:06:24.582Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://discuss.elastic.co/t/apm-server-8-12-1-security-update-esa-2024-03/352688"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.elastic.co/community/security"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "APM Server",
"vendor": "Elastic",
"versions": [
{
"lessThan": "8.12.1",
"status": "affected",
"version": "8.12",
"versionType": "semver"
}
]
}
],
"datePublic": "2024-02-06T22:35:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "An issue was discovered whereby APM Server could log at ERROR level, a response from Elasticsearch indicating that indexing the document failed and that response would contain parts of the original document. Depending on the nature of the document that the APM Server attempted to ingest, this could lead to the insertion of sensitive or private information in the APM Server logs."
}
],
"value": "An issue was discovered whereby APM Server could log at ERROR level, a response from Elasticsearch indicating that indexing the document failed and that response would contain parts of the original document. Depending on the nature of the document that the APM Server attempted to ingest, this could lead to the insertion of sensitive or private information in the APM Server logs."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.7,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-532",
"description": "CWE-532: Insertion of Sensitive Information into Log File",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-02-07T21:37:45.908Z",
"orgId": "271b6943-45a9-4f3a-ab4e-976f3fa05b5a",
"shortName": "elastic"
},
"references": [
{
"url": "https://discuss.elastic.co/t/apm-server-8-12-1-security-update-esa-2024-03/352688"
},
{
"url": "https://www.elastic.co/community/security"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "APM Server Insertion of Sensitive Information into Log File",
"x_generator": {
"engine": "Vulnogram 0.1.0-dev"
}
}
},
"cveMetadata": {
"assignerOrgId": "271b6943-45a9-4f3a-ab4e-976f3fa05b5a",
"assignerShortName": "elastic",
"cveId": "CVE-2024-23448",
"datePublished": "2024-02-07T21:37:45.908Z",
"dateReserved": "2024-01-16T21:31:26.030Z",
"dateUpdated": "2024-08-01T23:06:24.582Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2023-31421 (GCVE-0-2023-31421)
Vulnerability from cvelistv5
- CWE-295 - Improper Certificate Validation
| Vendor | Product | Version | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Elastic | Beats |
Version: 8.0.0, 8.9.2 |
|||||||||||||||||
|
|||||||||||||||||||
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T14:53:30.714Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://discuss.elastic.co/t/beats-elastic-agent-apm-server-and-fleet-server-8-10-1-security-update-improper-certificate-validation-issue-esa-2023-16/343385"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.elastic.co/community/security"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Beats",
"vendor": "Elastic",
"versions": [
{
"status": "affected",
"version": "8.0.0, 8.9.2"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Elastic Agent",
"vendor": "Elastic",
"versions": [
{
"status": "affected",
"version": "8.0.0, 8.9.2"
}
]
},
{
"defaultStatus": "unaffected",
"product": "APM Server",
"vendor": "Elastic",
"versions": [
{
"status": "affected",
"version": "8.0.0, 8.9.2"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Fleet Server",
"vendor": "Elastic",
"versions": [
{
"status": "affected",
"version": "8.0.0, 8.9.2"
}
]
}
],
"datePublic": "2023-09-19T15:32:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cspan style=\"background-color: var(--wht);\"\u003eIt was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whether the server certificate is valid for the target IP address; however, certificate signature validation is still performed. More specifically, when the client is configured to connect to an IP address (instead of a hostname) it does not validate the server certificate\u0027s IP SAN values against that IP address and certificate validation fails, and therefore the connection is not blocked as expected.\u003c/span\u003e"
}
],
"value": "It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whether the server certificate is valid for the target IP address; however, certificate signature validation is still performed. More specifically, when the client is configured to connect to an IP address (instead of a hostname) it does not validate the server certificate\u0027s IP SAN values against that IP address and certificate validation fails, and therefore the connection is not blocked as expected."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-295",
"description": "CWE-295: Improper Certificate Validation",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2023-10-26T03:10:52.684Z",
"orgId": "271b6943-45a9-4f3a-ab4e-976f3fa05b5a",
"shortName": "elastic"
},
"references": [
{
"url": "https://discuss.elastic.co/t/beats-elastic-agent-apm-server-and-fleet-server-8-10-1-security-update-improper-certificate-validation-issue-esa-2023-16/343385"
},
{
"url": "https://www.elastic.co/community/security"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Beats, Elastic Agent, APM Server, and Fleet Server Improper Certificate Validation issue",
"x_generator": {
"engine": "Vulnogram 0.1.0-dev"
}
}
},
"cveMetadata": {
"assignerOrgId": "271b6943-45a9-4f3a-ab4e-976f3fa05b5a",
"assignerShortName": "elastic",
"cveId": "CVE-2023-31421",
"datePublished": "2023-10-26T03:10:52.684Z",
"dateReserved": "2023-04-27T18:54:56.705Z",
"dateUpdated": "2024-08-02T14:53:30.714Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CERTFR-2026-AVI-1107
Vulnerability from certfr_avis
De multiples vulnérabilités ont été découvertes dans les produits Elastic. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et une atteinte à la confidentialité des données.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
| Vendor | Product | Description | ||
|---|---|---|---|---|
| Elastic | Elasticsearch | Elasticsearch versions 9.5.x antérieures à 9.5.1 | ||
| Elastic | Elasticsearch | Elasticsearch versions 9.4.x antérieures à 9.4.5 | ||
| Elastic | N/A | Winlogbeat versions antérieures à 8.13.0 | ||
| Elastic | Kibana | Kibana versions 9.5.x antérieures à 9.5.2 | ||
| Elastic | APM Server | APM Server versions 9.5.x antérieures à 9.5.1 | ||
| Elastic | N/A | Elastic Maps Server versions 8.19.x antérieures à 8.19.19 | ||
| Elastic | N/A | Filebeat versions 9.x antérieures à 9.3.1 | ||
| Elastic | APM Server | APM Server versions 9.4.x antérieures à 9.4.5 | ||
| Elastic | Elasticsearch | Elasticsearch versions 9.x antérieures à 9.3.8 | ||
| Elastic | Elasticsearch | Elasticsearch versions 8.x antérieures à 8.19.20 | ||
| Elastic | N/A | Elastic Cloud on Kubernetes versions antérieures à 3.5.0 | ||
| Elastic | Fleet Server | Fleet Server versions 9.x antérieures à 9.3.5 | ||
| Elastic | Elastic Agent | Elastic Agent versions 9.4.x antérieures à 9.4.6 | ||
| Elastic | Kibana | Kibana versions antérieures à 8.19.21 | ||
| Elastic | Elastic Agent | Elastic Agent versions 8.19.x antérieures à 8.19.21 | ||
| Elastic | APM Server | APM Server versions 8.19.x antérieures à 8.19.20 | ||
| Elastic | N/A | Filebeat versions 8.x antérieures à 8.19.18 | ||
| Elastic | Kibana | Kibana versions 9.x antérieures à 9.4.6 | ||
| Elastic | Fleet Server | Fleet Server versions 8.x antérieures à 8.19.16 | ||
| Elastic | N/A | Elastic Maps Server versions 9.4.x antérieures à 9.4.4 | ||
| Elastic | N/A | Elastic Maps Server versions 9.5.x antérieures à 9.5.1 | ||
| Elastic | Elastic Agent | Elastic Agent versions 9.5.x antérieures à 9.5.2 | ||
| Elastic | Elasticsearch | Elasticsearch versions antérieures à 9.3.0 | ||
| Elastic | Fleet Server | Fleet Server versions 9.4.x antérieures à 9.4.2 |
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [
{
"description": "Elasticsearch versions 9.5.x ant\u00e9rieures \u00e0 9.5.1",
"product": {
"name": "Elasticsearch",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "Elasticsearch versions 9.4.x ant\u00e9rieures \u00e0 9.4.5",
"product": {
"name": "Elasticsearch",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "Winlogbeat versions ant\u00e9rieures \u00e0 8.13.0",
"product": {
"name": "N/A",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "Kibana versions 9.5.x ant\u00e9rieures \u00e0 9.5.2",
"product": {
"name": "Kibana",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "APM Server versions 9.5.x ant\u00e9rieures \u00e0 9.5.1",
"product": {
"name": "APM Server",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "Elastic Maps Server versions 8.19.x ant\u00e9rieures \u00e0 8.19.19",
"product": {
"name": "N/A",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "Filebeat versions 9.x ant\u00e9rieures \u00e0 9.3.1",
"product": {
"name": "N/A",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "APM Server versions 9.4.x ant\u00e9rieures \u00e0 9.4.5",
"product": {
"name": "APM Server",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "Elasticsearch versions 9.x ant\u00e9rieures \u00e0 9.3.8",
"product": {
"name": "Elasticsearch",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "Elasticsearch versions 8.x ant\u00e9rieures \u00e0 8.19.20",
"product": {
"name": "Elasticsearch",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "Elastic Cloud on Kubernetes versions ant\u00e9rieures \u00e0 3.5.0",
"product": {
"name": "N/A",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "Fleet Server versions 9.x ant\u00e9rieures \u00e0 9.3.5",
"product": {
"name": "Fleet Server",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "Elastic Agent versions 9.4.x ant\u00e9rieures \u00e0 9.4.6",
"product": {
"name": "Elastic Agent",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "Kibana versions ant\u00e9rieures \u00e0 8.19.21",
"product": {
"name": "Kibana",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "Elastic Agent versions 8.19.x ant\u00e9rieures \u00e0 8.19.21",
"product": {
"name": "Elastic Agent",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "APM Server versions 8.19.x ant\u00e9rieures \u00e0 8.19.20",
"product": {
"name": "APM Server",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "Filebeat versions 8.x ant\u00e9rieures \u00e0 8.19.18",
"product": {
"name": "N/A",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "Kibana versions 9.x ant\u00e9rieures \u00e0 9.4.6",
"product": {
"name": "Kibana",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "Fleet Server versions 8.x ant\u00e9rieures \u00e0 8.19.16",
"product": {
"name": "Fleet Server",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "Elastic Maps Server versions 9.4.x ant\u00e9rieures \u00e0 9.4.4",
"product": {
"name": "N/A",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "Elastic Maps Server versions 9.5.x ant\u00e9rieures \u00e0 9.5.1",
"product": {
"name": "N/A",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "Elastic Agent versions 9.5.x ant\u00e9rieures \u00e0 9.5.2",
"product": {
"name": "Elastic Agent",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "Elasticsearch versions ant\u00e9rieures \u00e0 9.3.0",
"product": {
"name": "Elasticsearch",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "Fleet Server versions 9.4.x ant\u00e9rieures \u00e0 9.4.2",
"product": {
"name": "Fleet Server",
"vendor": {
"name": "Elastic",
"scada": false
}
}
}
],
"affected_systems_content": "",
"content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
"cves": [
{
"name": "CVE-2026-72628",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72628"
},
{
"name": "CVE-2026-63138",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63138"
},
{
"name": "CVE-2026-78601",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-78601"
},
{
"name": "CVE-2026-78591",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-78591"
},
{
"name": "CVE-2026-78590",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-78590"
},
{
"name": "CVE-2026-78588",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-78588"
},
{
"name": "CVE-2026-78609",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-78609"
},
{
"name": "CVE-2026-63137",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-63137"
},
{
"name": "CVE-2026-78605",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-78605"
},
{
"name": "CVE-2026-78600",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-78600"
},
{
"name": "CVE-2026-72644",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72644"
},
{
"name": "CVE-2026-78606",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-78606"
},
{
"name": "CVE-2026-78599",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-78599"
},
{
"name": "CVE-2026-72649",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72649"
},
{
"name": "CVE-2026-78602",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-78602"
},
{
"name": "CVE-2026-82293",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-82293"
},
{
"name": "CVE-2024-14047",
"url": "https://www.cve.org/CVERecord?id=CVE-2024-14047"
},
{
"name": "CVE-2026-78604",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-78604"
},
{
"name": "CVE-2026-78592",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-78592"
},
{
"name": "CVE-2026-78586",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-78586"
},
{
"name": "CVE-2026-78598",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-78598"
},
{
"name": "CVE-2026-78607",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-78607"
},
{
"name": "CVE-2026-78597",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-78597"
},
{
"name": "CVE-2026-78587",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-78587"
},
{
"name": "CVE-2026-56143",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-56143"
},
{
"name": "CVE-2026-72641",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72641"
},
{
"name": "CVE-2026-78594",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-78594"
},
{
"name": "CVE-2026-78584",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-78584"
},
{
"name": "CVE-2026-72654",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72654"
},
{
"name": "CVE-2015-5531",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-5531"
},
{
"name": "CVE-2026-72652",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-72652"
}
],
"initial_release_date": "2026-09-02T00:00:00",
"last_revision_date": "2026-09-02T00:00:00",
"links": [],
"reference": "CERTFR-2026-AVI-1107",
"revisions": [
{
"description": "Version initiale",
"revision_date": "2026-09-02T00:00:00.000000"
}
],
"risks": [
{
"description": "D\u00e9ni de service \u00e0 distance"
},
{
"description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
},
{
"description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
},
{
"description": "Injection SQL (SQLi)"
},
{
"description": "Contournement de la politique de s\u00e9curit\u00e9"
},
{
"description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
},
{
"description": "\u00c9l\u00e9vation de privil\u00e8ges"
}
],
"summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits Elastic. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, une \u00e9l\u00e9vation de privil\u00e8ges et une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es.",
"title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits Elastic",
"vendor_advisories": [
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390107",
"url": "https://discuss.elastic.co/t/kibana-9-4-5-security-update-esa-2026-147/390107"
},
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390118",
"url": "https://discuss.elastic.co/t/filebeat-8-19-18-9-3-1-security-update-esa-2026-165/390118"
},
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390088",
"url": "https://discuss.elastic.co/t/kibana-9-4-5-9-5-1-security-update-esa-2026-115/390088"
},
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390082",
"url": "https://discuss.elastic.co/t/kibana-9-4-5-9-5-1-security-update-esa-2026-168/390082"
},
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390085",
"url": "https://discuss.elastic.co/t/kibana-8-19-19-9-3-5-security-update-esa-2026-48/390085"
},
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390110",
"url": "https://discuss.elastic.co/t/apm-server-8-19-20-9-4-5-9-5-1-security-update-esa-2026-152/390110"
},
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390044",
"url": "https://discuss.elastic.co/t/winlogbeat-8-13-0-security-update-esa-2024-49/390044"
},
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390115",
"url": "https://discuss.elastic.co/t/kibana-9-4-4-security-update-esa-2026-161/390115"
},
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390091",
"url": "https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-9-5-2-security-update-esa-2026-135/390091"
},
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390105",
"url": "https://discuss.elastic.co/t/elastic-cloud-on-kubernetes-3-5-0-security-update-esa-2026-145/390105"
},
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390086",
"url": "https://discuss.elastic.co/t/kibana-9-4-3-security-update-esa-2026-61/390086"
},
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390117",
"url": "https://discuss.elastic.co/t/fleet-server-8-19-16-9-3-5-9-4-2-security-update-esa-2026-164/390117"
},
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390092",
"url": "https://discuss.elastic.co/t/elasticsearch-8-19-20-9-4-5-9-5-1-security-update-esa-2026-141/390092"
},
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390077",
"url": "https://discuss.elastic.co/t/kibana-8-19-16-9-3-5-9-4-2-security-update-esa-2026-160/390077"
},
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390094",
"url": "https://discuss.elastic.co/t/elasticsearch-8-19-19-9-3-8-9-4-4-9-5-1-security-update-esa-2026-143/390094"
},
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390093",
"url": "https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-9-5-2-security-update-esa-2026-142/390093"
},
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390108",
"url": "https://discuss.elastic.co/t/elastic-maps-server-8-19-19-9-4-4-9-5-1-security-update-esa-2026-148/390108"
},
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390109",
"url": "https://discuss.elastic.co/t/elastic-agent-8-19-21-9-4-6-9-5-2-security-update-esa-2026-150/390109"
},
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390112",
"url": "https://discuss.elastic.co/t/kibana-8-19-18-9-4-3-security-update-esa-2026-157/390112"
},
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390119",
"url": "https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-9-5-2-security-update-esa-2026-169/390119"
},
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390087",
"url": "https://discuss.elastic.co/t/elasticsearch-8-19-20-9-4-5-9-5-1-security-update-esa-2026-114/390087"
},
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390114",
"url": "https://discuss.elastic.co/t/kibana-8-19-17-9-3-6-9-4-3-security-update-esa-2026-159/390114"
},
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390111",
"url": "https://discuss.elastic.co/t/kibana-8-19-19-9-3-8-9-4-4-security-update-esa-2026-156/390111"
},
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390106",
"url": "https://discuss.elastic.co/t/elastic-cloud-on-kubernetes-3-5-0-security-update-esa-2026-146/390106"
},
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390116",
"url": "https://discuss.elastic.co/t/kibana-8-19-16-9-3-5-9-4-2-security-update-esa-2026-163/390116"
},
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390113",
"url": "https://discuss.elastic.co/t/kibana-8-19-18-9-3-6-9-4-3-security-update-esa-2026-158/390113"
},
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390089",
"url": "https://discuss.elastic.co/t/kibana-9-4-6-9-5-1-security-update-esa-2026-122/390089"
},
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390084",
"url": "https://discuss.elastic.co/t/elasticsearch-8-19-20-9-3-0-security-update-esa-2026-47/390084"
},
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390072",
"url": "https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-security-update-esa-2026-155/390072"
},
{
"published_at": "2026-09-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 390090",
"url": "https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-9-5-2-security-update-esa-2026-125/390090"
}
]
}
CERTFR-2025-AVI-0636
Vulnerability from certfr_avis
De multiples vulnérabilités ont été découvertes dans les produits Elastic. Elles permettent à un attaquant de provoquer une élévation de privilèges.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
| Vendor | Product | Description | ||
|---|---|---|---|---|
| Elastic | APM Server | APM Server versions antérieures à 8.16.3 | ||
| Elastic | Beats | Beats versions antérieures à 9.1.0 | ||
| Elastic | APM Server | APM Server versions 8.17.x antérieures à 8.17.1 |
| Title | Publication Time | Tags | ||||||
|---|---|---|---|---|---|---|---|---|
|
||||||||
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [
{
"description": "APM Server versions ant\u00e9rieures \u00e0 8.16.3",
"product": {
"name": "APM Server",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "Beats versions ant\u00e9rieures \u00e0 9.1.0",
"product": {
"name": "Beats",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "APM Server versions 8.17.x ant\u00e9rieures \u00e0 8.17.1",
"product": {
"name": "APM Server",
"vendor": {
"name": "Elastic",
"scada": false
}
}
}
],
"affected_systems_content": "",
"content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
"cves": [
{
"name": "CVE-2025-25011",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-25011"
},
{
"name": "CVE-2025-0712",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-0712"
}
],
"initial_release_date": "2025-07-30T00:00:00",
"last_revision_date": "2025-07-30T00:00:00",
"links": [],
"reference": "CERTFR-2025-AVI-0636",
"revisions": [
{
"description": "Version initiale",
"revision_date": "2025-07-30T00:00:00.000000"
}
],
"risks": [
{
"description": "\u00c9l\u00e9vation de privil\u00e8ges"
}
],
"summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits Elastic. Elles permettent \u00e0 un attaquant de provoquer une \u00e9l\u00e9vation de privil\u00e8ges.",
"title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits Elastic",
"vendor_advisories": [
{
"published_at": "2025-07-29",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic ESA-2025-01",
"url": "https://discuss.elastic.co/t/apm-server-windows-installer-8-16-3-8-17-1-security-update-esa-2025-01/380557"
},
{
"published_at": "2025-07-29",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic ESA-2025-12",
"url": "https://discuss.elastic.co/t/beats-windows-installer-9-1-0-security-update-esa-2025-12/380558"
}
]
}
CERTFR-2025-AVI-0359
Vulnerability from certfr_avis
De multiples vulnérabilités ont été découvertes dans les produits Elastic. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
| Vendor | Product | Description | ||
|---|---|---|---|---|
| Elastic | Elasticsearch | Elasticsearch versions antérieures à 7.17.25 | ||
| Elastic | Kibana | Kibana versions 7.17.x postérieures à 7.14.6 et antérieures à 7.17.24 | ||
| Elastic | APM Server | APM Server versions 8.x antérieures à 8.16.1 | ||
| Elastic | Elasticsearch | Elasticsearch versions antérieures à 8.16.0 | ||
| Elastic | Logstash | Logstash versions 8.15.x antérieures à 8.15.3 | ||
| Elastic | Elastic Agent | Elastic Agent versions antérieures à 8.15.4 | ||
| Elastic | Elastic Agent | Elastic Agent versions antérieures à 7.17.25 | ||
| Elastic | Kibana | Kibana versions 8.x antérieures à 8.13.0 |
| Title | Publication Time | Tags | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [
{
"description": "Elasticsearch versions ant\u00e9rieures \u00e0 7.17.25",
"product": {
"name": "Elasticsearch",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "Kibana versions 7.17.x post\u00e9rieures \u00e0 7.14.6 et ant\u00e9rieures \u00e0 7.17.24",
"product": {
"name": "Kibana",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "APM Server versions 8.x ant\u00e9rieures \u00e0 8.16.1",
"product": {
"name": "APM Server",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "Elasticsearch versions ant\u00e9rieures \u00e0 8.16.0",
"product": {
"name": "Elasticsearch",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "Logstash versions 8.15.x ant\u00e9rieures \u00e0 8.15.3",
"product": {
"name": "Logstash",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "Elastic Agent versions ant\u00e9rieures \u00e0 8.15.4",
"product": {
"name": "Elastic Agent",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "Elastic Agent versions ant\u00e9rieures \u00e0 7.17.25",
"product": {
"name": "Elastic Agent",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "Kibana versions 8.x ant\u00e9rieures \u00e0 8.13.0",
"product": {
"name": "Kibana",
"vendor": {
"name": "Elastic",
"scada": false
}
}
}
],
"affected_systems_content": "",
"content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
"cves": [
{
"name": "CVE-2024-47561",
"url": "https://www.cve.org/CVERecord?id=CVE-2024-47561"
},
{
"name": "CVE-2023-46669",
"url": "https://www.cve.org/CVERecord?id=CVE-2023-46669"
},
{
"name": "CVE-2024-52979",
"url": "https://www.cve.org/CVERecord?id=CVE-2024-52979"
},
{
"name": "CVE-2024-11994",
"url": "https://www.cve.org/CVERecord?id=CVE-2024-11994"
},
{
"name": "CVE-2024-11390",
"url": "https://www.cve.org/CVERecord?id=CVE-2024-11390"
},
{
"name": "CVE-2025-25016",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-25016"
},
{
"name": "CVE-2024-52976",
"url": "https://www.cve.org/CVERecord?id=CVE-2024-52976"
}
],
"initial_release_date": "2025-05-02T00:00:00",
"last_revision_date": "2025-05-02T00:00:00",
"links": [],
"reference": "CERTFR-2025-AVI-0359",
"revisions": [
{
"description": "Version initiale",
"revision_date": "2025-05-02T00:00:00.000000"
}
],
"risks": [
{
"description": "D\u00e9ni de service \u00e0 distance"
},
{
"description": "Injection de code indirecte \u00e0 distance (XSS)"
},
{
"description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
},
{
"description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
},
{
"description": "Contournement de la politique de s\u00e9curit\u00e9"
},
{
"description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
}
],
"summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits Elastic. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, un d\u00e9ni de service \u00e0 distance et une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es.",
"title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits Elastic",
"vendor_advisories": [
{
"published_at": "2025-05-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic ESA-2024-47",
"url": "https://discuss.elastic.co/t/kibana-7-17-19-and-8-13-0-security-update-esa-2024-47/377711"
},
{
"published_at": "2025-05-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic ESA-2024-39",
"url": "https://discuss.elastic.co/t/elastic-agent-7-17-25-and-8-15-4-security-update-esa-2024-39/377708"
},
{
"published_at": "2025-05-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic ESA-2025-03",
"url": "https://discuss.elastic.co/t/elastic-agent-elastic-endpoint-security-security-update-esa-2025-03/377706"
},
{
"published_at": "2025-05-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic ESA-2024-20",
"url": "https://discuss.elastic.co/t/kibana-7-17-24-and-8-12-0-security-update-esa-2024-20/377712"
},
{
"published_at": "2025-05-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic ESA-2024-38",
"url": "https://discuss.elastic.co/t/logstash-8-15-3-security-update-esa-2024-38/377707"
},
{
"published_at": "2025-05-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic ESA-2024-40",
"url": "https://discuss.elastic.co/t/elasticsearch-7-17-25-and-8-16-0-security-update-esa-2024-40/377709"
},
{
"published_at": "2025-05-01",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic ESA-2024-41",
"url": "https://discuss.elastic.co/t/apm-server-8-16-1-security-update-esa-2024-41/377710"
}
]
}
CERTFR-2024-AVI-0690
Vulnerability from certfr_avis
Une vulnérabilité a été découverte dans Elastic APM Server. Elle permet à un attaquant de provoquer une atteinte à la confidentialité des données.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
| Vendor | Product | Description | ||
|---|---|---|---|---|
| Elastic | APM Server | APM Server versions antérieures à 7.17.21 | ||
| Elastic | APM Server | APM Server versions antérieures à 8.14.0 |
| Title | Publication Time | Tags | |||
|---|---|---|---|---|---|
|
|||||
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [
{
"description": "APM Server versions ant\u00e9rieures \u00e0 7.17.21",
"product": {
"name": "APM Server",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "APM Server versions ant\u00e9rieures \u00e0 8.14.0",
"product": {
"name": "APM Server",
"vendor": {
"name": "Elastic",
"scada": false
}
}
}
],
"affected_systems_content": "",
"content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
"cves": [
{
"name": "CVE-2023-45288",
"url": "https://www.cve.org/CVERecord?id=CVE-2023-45288"
}
],
"initial_release_date": "2024-08-16T00:00:00",
"last_revision_date": "2024-08-16T00:00:00",
"links": [],
"reference": "CERTFR-2024-AVI-0690",
"revisions": [
{
"description": "Version initiale",
"revision_date": "2024-08-16T00:00:00.000000"
}
],
"risks": [
{
"description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
}
],
"summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans Elastic APM Server. Elle permet \u00e0 un attaquant de provoquer une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es.",
"title": "Vuln\u00e9rabilit\u00e9 dans Elastic APM Server",
"vendor_advisories": [
{
"published_at": "2024-08-15",
"title": "Bulletin de s\u00e9curit\u00e9 Elastic 364946",
"url": "https://discuss.elastic.co/t/apm-server-8-14-0-security-update-esa-2024-09/364946"
}
]
}
CERTFR-2024-AVI-0099
Vulnerability from certfr_avis
De multiples vulnérabilités ont été découvertes dans les produits ElasticSearch. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données et un contournement de la politique de sécurité.
Solution
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
None| Title | Publication Time | Tags | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [
{
"description": "Elastic Network Drive Connector versions ant\u00e9rieures \u00e0 8.12.1.",
"product": {
"name": "N/A",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "APM Server versions ant\u00e9rieures \u00e0 8.12.1",
"product": {
"name": "APM Server",
"vendor": {
"name": "Elastic",
"scada": false
}
}
},
{
"description": "Kibana versions ant\u00e9rieures \u00e0 8.12.1",
"product": {
"name": "Kibana",
"vendor": {
"name": "Elastic",
"scada": false
}
}
}
],
"affected_systems_content": null,
"content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
"cves": [
{
"name": "CVE-2024-23446",
"url": "https://www.cve.org/CVERecord?id=CVE-2024-23446"
},
{
"name": "CVE-2024-23448",
"url": "https://www.cve.org/CVERecord?id=CVE-2024-23448"
},
{
"name": "CVE-2024-23447",
"url": "https://www.cve.org/CVERecord?id=CVE-2024-23447"
}
],
"initial_release_date": "2024-02-07T00:00:00",
"last_revision_date": "2024-02-07T00:00:00",
"links": [
{
"title": "Bulletin de s\u00e9curit\u00e9 Elastic ESA-2024-02\u00a0 du 06 f\u00e9vrier 2024",
"url": "https://discuss.elastic.co/t/elastic-network-drive-connector-8-12-1-security-update-esa-2024-02/352687"
},
{
"title": "Bulletin de s\u00e9curit\u00e9 Elastic ESA-2024-03 du 06 f\u00e9vrier 2024",
"url": "https://discuss.elastic.co/t/apm-server-8-12-1-security-update-esa-2024-03/352688"
}
],
"reference": "CERTFR-2024-AVI-0099",
"revisions": [
{
"description": "Version initiale",
"revision_date": "2024-02-07T00:00:00.000000"
}
],
"risks": [
{
"description": "Contournement de la politique de s\u00e9curit\u00e9"
},
{
"description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
}
],
"summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans \u003cspan\nclass=\"textit\"\u003eles produits ElasticSearch\u003c/span\u003e. Elles permettent \u00e0 un\nattaquant de provoquer une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es et\nun contournement de la politique de s\u00e9curit\u00e9.\n",
"title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits Elastic",
"vendor_advisories": [
{
"published_at": null,
"title": "Bulletin de s\u00e9curit\u00e9 Elastic ESA-2024-01 du 06 f\u00e9vrier 2024",
"url": "https://discuss.elastic.co/t/kibana-8-12-1-security-update-esa-2024-01/352686"
},
{
"published_at": null,
"title": "Bulletin de s\u00e9curit\u00e9 Elastic ESA-2024-023 du 06 f\u00e9vrier 2024",
"url": null
},
{
"published_at": null,
"title": "Bulletin de s\u00e9curit\u00e9 Elastic ESA-2024-02 du 06 f\u00e9vrier 2024",
"url": null
}
]
}