Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta feature. Using this vector, an attacker whose website is being crawled by App Search could craft a malicious sitemap.xml to traverse the filesystem of the host running the instance and obtain sensitive files.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NElastic App Search
APPElastic7.11.0 – 7.12.0 (bez)
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
XXE
Powiązane podatności
CVE-2020-7011MEDIUM6.1ten sam produkt
Elastic App Search versions before 7.7.0 contain a cross site scripting (XSS) flaw when displaying document UR...
CVE-2019-7609CRITICAL10.0⚠ KEVPL ✓ten sam vendor
RCE w Kibana Timelion — wykonanie kodu z uprawnieniami procesu
CVE-2015-1427CRITICAL9.8⚠ KEVPL ✓ten sam vendor
Elasticsearch: ucieczka z sandboksa Groovy i zdalne wykonanie poleceń
CVE-2025-37729CRITICAL9.1PL ✓ten sam vendor
Elastic Cloud Enterprise — Server-Side Template Injection (SSTI) w silniku Jinjava
CVE-2025-25014CRITICAL9.1PL ✓ten sam vendor
Prototype Pollution w Kibana prowadzące do RCE przez HTTP