Meet Corgea at Black Hat, BSides Las Vegas & DEF CON
maven

org.elasticsearch:elasticsearch

View on maven registry
44 Total advisories
44 Vulnerabilities
0 Malware

Vulnerabilities

MEDIUM 6.5
Maven

CVE-2024-52980

Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function

MEDIUM 6.8
Maven

CVE-2025-37731

Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates

MEDIUM 4.4
Maven

CVE-2024-23451

Elasticsearch Incorrect Authorization vulnerability

MEDIUM 5.7
Maven

CVE-2025-37727

Elasticsearch: Insertion of Sensitive Information into Log File via reindex API

UNKNOWN
Maven

CVE-2024-12539

Elasticsearch Incorrect Authorization vulnerability

MEDIUM 4.9
Maven

CVE-2024-37280

Elasticsearch StackOverflow vulnerability

MEDIUM 4.9
Maven

CVE-2024-23450

Elasticsearch Uncontrolled Resource Consumption vulnerability

MEDIUM 4.9
Maven

CVE-2024-23444

Elasticsearch stores private key on disk unencrypted

HIGH 7.5
Maven

CVE-2023-31418

Elasticsearch vulnerable to Uncontrolled Resource Consumption

HIGH 8.1
Maven KEV

CVE-2014-3120

Elasticsearch Improper Access Control vulnerability

MEDIUM 6.5
Maven

CVE-2024-52979

Elasticsearch Uncontrolled Resource Consumption Vulnerability

MEDIUM 4.3
Maven

CVE-2024-23449

Elasticsearch Uncaught Exception leading to crash

MEDIUM 4.9
Maven

CVE-2024-52981

Elasticsearch Vulnerable to Stack Overflow due to a Large Recursion

MEDIUM 6.5
Maven

CVE-2024-43709

Elasticsearch allocation of resources without limits or throttling leads to crash

MEDIUM 4.1
Maven

CVE-2023-31417

Elasticsearch allows insertion of sensitive information into log files when using deprecated URIs

UNKNOWN
Maven

CVE-2015-3337

Improper Limitation of a Pathname to a Restricted Directory in Elasticsearch

UNKNOWN
Maven

CVE-2015-5531

Improper Limitation of a Pathname to a Restricted Directory in Elasticsearch

UNKNOWN
Maven KEV

CVE-2015-1427

Improper Access Control in Elasticsearch

UNKNOWN
Maven

CVE-2014-6439

Cross-site scripting in Elasticsearch

MEDIUM 5.2
Maven

CVE-2023-49921

Elasticsearch Insertion of Sensitive Information into Log File

MEDIUM 6.5
Maven

CVE-2023-31419

Elasticsearch vulnerable to stack overflow in the search API

MEDIUM 4.3
Maven

CVE-2021-22134

Exposure of Sensitive Information to an Unauthorized Actor

LOW 3.1
Maven

CVE-2020-7020

Privilege Context Switching Error in Elasticsearch

HIGH 7.5
Maven

CVE-2022-23712

Improper Check for Unusual or Exceptional Conditions in Elasticsearch

HIGH 8.8
Maven

CVE-2020-7009

Improper Privilege Management in Elasticsearch

MEDIUM 4.9
Maven

CVE-2020-7021

Insertion of Sensitive Information into Log File in Elasticsearch

MEDIUM 6.1
Maven

GHSA-m6gg-86c6-gfr9

Withdrawn: Cross-site Scripting in Kibana

MEDIUM 5.7
Maven

CVE-2021-22144

Denial of Service in Elasticsearch

MEDIUM 5.9
Maven

CVE-2019-7614

Concurrent Execution using Shared Resource with Improper Synchronization in Elasticsearch

MEDIUM 5.3
Maven

CVE-2021-22137

Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch

HIGH 7.5
Maven

CVE-2015-4165

Improper Access Control in Elasticsearch

MEDIUM 4.3
Maven

CVE-2022-23708

Elasticsearch privilege escalation

MEDIUM 6.5
Maven

CVE-2020-7019

Improper privilege management in elasticsearch

MEDIUM 5.3
Maven

CVE-2021-22135

API information disclosure flaw in Elasticsearch

HIGH 8.8
Maven

CVE-2020-7014

Privilege Escalation Flaw in Elasticsearch

MEDIUM 4.8
Maven

CVE-2021-22132

Insufficiently Protected Credentials in Elasticsearch

MEDIUM 6.5
Maven

CVE-2021-22147

Exposure of sensitive information in Elasticsearch

MEDIUM 6.1
Maven

CVE-2018-3824

Elasticsearch subject to cross site scripting

MEDIUM 6.5
Maven

CVE-2023-46673

Elasticsearch Improper Handling of Exceptional Conditions

MEDIUM 5.3
Maven

CVE-2019-7619

Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch

HIGH 8.1
Maven

CVE-2019-7611

Improper Access Control in Elasticsearch

HIGH 8.8
Maven

CVE-2018-3831

Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch

MEDIUM 5.9
Maven

CVE-2018-17247

Improper Restriction of XML External Entity Reference in Elasticsearch

MEDIUM 6.5
Maven

CVE-2018-17244

Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch

Ready to move

Start Securing

Free, no credit card | First findings in minutes