Elastic
Elastic Cloud Enterprise: vulnerabilidades y CVE
Elastic Cloud Enterprise tiene 9 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses2
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-37736 | Alta (8.8) | 0.38% | — | 7 nov 2025 | Improper Authorization in Elastic Cloud Enterprise can lead to Privilege Escalation where the built-in readonly user can call APIs that should not be allowed. The list of APIs that are affected by this issue is:… |
| CVE-2025-37729 | Alta (7.2) | 0.66% | — | 13 oct 2025 | Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin access exfiltrating sensitive information and issuing commands via a… |
| CVE-2024-37282 | Crítica (9.8) | 0.60% | — | 28 jun 2024 | It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subsequently used to create new API keys that have elevated privileges. |
| CVE-2023-31418 | Alta (7.5) | 2.1% | — | 26 oct 2023 | An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number… |
| CVE-2022-23716 | Media (5.3) | 0.64% | — | 28 sept 2022 | A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in deployment logs in the Logging and Monitoring cluster. |
| CVE-2022-23715 | Media (6.5) | 0.80% | — | 25 ago 2022 | A flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwords and Elasticsearch keystore settings values in logs such as the audit log or deployment logs in… |
| CVE-2018-3829 | Media (5.3) | 0.90% | — | 19 sept 2018 | In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invalid roles token. An attacker with access to the previous runner ID and IP… |
| CVE-2018-3828 | Alta (7.5) | 0.60% | — | 19 sept 2018 | Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exception conditions would result in encryption keys, passwords, and other security… |
| CVE-2018-3825 | Media (5.9) | 0.65% | — | 19 sept 2018 | In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 a default master encryption key is used in the process of granting ZooKeeper access to Elasticsearch clusters. Unless explicitly overwritten, this master key is… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.