Dependency scanning
Check whether org.elasticsearch:elasticsearch is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2024-52980
Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function
CVE-2025-37731
Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates
CVE-2024-23451
Elasticsearch Incorrect Authorization vulnerability
CVE-2025-37727
Elasticsearch: Insertion of Sensitive Information into Log File via reindex API
CVE-2024-12539
Elasticsearch Incorrect Authorization vulnerability
CVE-2024-37280
Elasticsearch StackOverflow vulnerability
CVE-2024-23450
Elasticsearch Uncontrolled Resource Consumption vulnerability
CVE-2024-23444
Elasticsearch stores private key on disk unencrypted
CVE-2023-31418
Elasticsearch vulnerable to Uncontrolled Resource Consumption
CVE-2014-3120
Elasticsearch Improper Access Control vulnerability
CVE-2024-52979
Elasticsearch Uncontrolled Resource Consumption Vulnerability
CVE-2024-23449
Elasticsearch Uncaught Exception leading to crash
CVE-2024-52981
Elasticsearch Vulnerable to Stack Overflow due to a Large Recursion
CVE-2024-43709
Elasticsearch allocation of resources without limits or throttling leads to crash
CVE-2023-31417
Elasticsearch allows insertion of sensitive information into log files when using deprecated URIs
CVE-2015-3337
Improper Limitation of a Pathname to a Restricted Directory in Elasticsearch
CVE-2015-5531
Improper Limitation of a Pathname to a Restricted Directory in Elasticsearch
CVE-2015-1427
Improper Access Control in Elasticsearch
CVE-2014-6439
Cross-site scripting in Elasticsearch
CVE-2023-49921
Elasticsearch Insertion of Sensitive Information into Log File
CVE-2023-31419
Elasticsearch vulnerable to stack overflow in the search API
CVE-2021-22134
Exposure of Sensitive Information to an Unauthorized Actor
CVE-2020-7020
Privilege Context Switching Error in Elasticsearch
CVE-2022-23712
Improper Check for Unusual or Exceptional Conditions in Elasticsearch
CVE-2020-7009
Improper Privilege Management in Elasticsearch
CVE-2020-7021
Insertion of Sensitive Information into Log File in Elasticsearch
GHSA-m6gg-86c6-gfr9
Withdrawn: Cross-site Scripting in Kibana
CVE-2021-22144
Denial of Service in Elasticsearch
CVE-2019-7614
Concurrent Execution using Shared Resource with Improper Synchronization in Elasticsearch
CVE-2021-22137
Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch
CVE-2015-4165
Improper Access Control in Elasticsearch
CVE-2022-23708
Elasticsearch privilege escalation
CVE-2020-7019
Improper privilege management in elasticsearch
CVE-2021-22135
API information disclosure flaw in Elasticsearch
CVE-2020-7014
Privilege Escalation Flaw in Elasticsearch
CVE-2021-22132
Insufficiently Protected Credentials in Elasticsearch
CVE-2021-22147
Exposure of sensitive information in Elasticsearch
CVE-2018-3824
Elasticsearch subject to cross site scripting
CVE-2023-46673
Elasticsearch Improper Handling of Exceptional Conditions
CVE-2019-7619
Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch
CVE-2019-7611
Improper Access Control in Elasticsearch
CVE-2018-3831
Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch
CVE-2018-17247
Improper Restriction of XML External Entity Reference in Elasticsearch
CVE-2018-17244
Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch
Browse more Maven advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes