maven

org.elasticsearch:elasticsearch

View on maven registry
44 Total advisories
44 Vulnerabilities
0 Malware

Dependency scanning

Check whether org.elasticsearch:elasticsearch is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 6.5
Maven

CVE-2024-52980

Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function

MEDIUM 6.8
Maven

CVE-2025-37731

Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates

MEDIUM 4.4
Maven

CVE-2024-23451

Elasticsearch Incorrect Authorization vulnerability

MEDIUM 5.7
Maven

CVE-2025-37727

Elasticsearch: Insertion of Sensitive Information into Log File via reindex API

UNKNOWN
Maven

CVE-2024-12539

Elasticsearch Incorrect Authorization vulnerability

MEDIUM 4.9
Maven

CVE-2024-37280

Elasticsearch StackOverflow vulnerability

MEDIUM 4.9
Maven

CVE-2024-23450

Elasticsearch Uncontrolled Resource Consumption vulnerability

MEDIUM 4.9
Maven

CVE-2024-23444

Elasticsearch stores private key on disk unencrypted

HIGH 7.5
Maven

CVE-2023-31418

Elasticsearch vulnerable to Uncontrolled Resource Consumption

HIGH 8.1
Maven KEV

CVE-2014-3120

Elasticsearch Improper Access Control vulnerability

MEDIUM 6.5
Maven

CVE-2024-52979

Elasticsearch Uncontrolled Resource Consumption Vulnerability

MEDIUM 4.3
Maven

CVE-2024-23449

Elasticsearch Uncaught Exception leading to crash

MEDIUM 4.9
Maven

CVE-2024-52981

Elasticsearch Vulnerable to Stack Overflow due to a Large Recursion

MEDIUM 6.5
Maven

CVE-2024-43709

Elasticsearch allocation of resources without limits or throttling leads to crash

MEDIUM 4.1
Maven

CVE-2023-31417

Elasticsearch allows insertion of sensitive information into log files when using deprecated URIs

UNKNOWN
Maven

CVE-2015-3337

Improper Limitation of a Pathname to a Restricted Directory in Elasticsearch

UNKNOWN
Maven

CVE-2015-5531

Improper Limitation of a Pathname to a Restricted Directory in Elasticsearch

UNKNOWN
Maven KEV

CVE-2015-1427

Improper Access Control in Elasticsearch

UNKNOWN
Maven

CVE-2014-6439

Cross-site scripting in Elasticsearch

MEDIUM 5.2
Maven

CVE-2023-49921

Elasticsearch Insertion of Sensitive Information into Log File

MEDIUM 6.5
Maven

CVE-2023-31419

Elasticsearch vulnerable to stack overflow in the search API

MEDIUM 4.3
Maven

CVE-2021-22134

Exposure of Sensitive Information to an Unauthorized Actor

LOW 3.1
Maven

CVE-2020-7020

Privilege Context Switching Error in Elasticsearch

HIGH 7.5
Maven

CVE-2022-23712

Improper Check for Unusual or Exceptional Conditions in Elasticsearch

HIGH 8.8
Maven

CVE-2020-7009

Improper Privilege Management in Elasticsearch

MEDIUM 4.9
Maven

CVE-2020-7021

Insertion of Sensitive Information into Log File in Elasticsearch

MEDIUM 6.1
Maven

GHSA-m6gg-86c6-gfr9

Withdrawn: Cross-site Scripting in Kibana

MEDIUM 5.7
Maven

CVE-2021-22144

Denial of Service in Elasticsearch

MEDIUM 5.9
Maven

CVE-2019-7614

Concurrent Execution using Shared Resource with Improper Synchronization in Elasticsearch

MEDIUM 5.3
Maven

CVE-2021-22137

Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch

HIGH 7.5
Maven

CVE-2015-4165

Improper Access Control in Elasticsearch

MEDIUM 4.3
Maven

CVE-2022-23708

Elasticsearch privilege escalation

MEDIUM 6.5
Maven

CVE-2020-7019

Improper privilege management in elasticsearch

MEDIUM 5.3
Maven

CVE-2021-22135

API information disclosure flaw in Elasticsearch

HIGH 8.8
Maven

CVE-2020-7014

Privilege Escalation Flaw in Elasticsearch

MEDIUM 4.8
Maven

CVE-2021-22132

Insufficiently Protected Credentials in Elasticsearch

MEDIUM 6.5
Maven

CVE-2021-22147

Exposure of sensitive information in Elasticsearch

MEDIUM 6.1
Maven

CVE-2018-3824

Elasticsearch subject to cross site scripting

MEDIUM 6.5
Maven

CVE-2023-46673

Elasticsearch Improper Handling of Exceptional Conditions

MEDIUM 5.3
Maven

CVE-2019-7619

Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch

HIGH 8.1
Maven

CVE-2019-7611

Improper Access Control in Elasticsearch

HIGH 8.8
Maven

CVE-2018-3831

Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch

MEDIUM 5.9
Maven

CVE-2018-17247

Improper Restriction of XML External Entity Reference in Elasticsearch

MEDIUM 6.5
Maven

CVE-2018-17244

Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes