Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta feature. Using this vector, an attacker whose website is being crawled by App Search could craft a malicious sitemap.xml to traverse the filesystem of the host running the instance and obtain sensitive files.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NElastic App Search
APPElastic7.11.0 – 7.12.0 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
XXE
Related vulnerabilities
CVE-2020-7011MEDIUM6.1same product
Elastic App Search versions before 7.7.0 contain a cross site scripting (XSS) flaw when displaying document UR...
CVE-2019-7609CRITICAL10.0⚠ KEVPL ✓same vendor
RCE w Kibana Timelion — wykonanie kodu z uprawnieniami procesu
CVE-2015-1427CRITICAL9.8⚠ KEVPL ✓same vendor
Elasticsearch: ucieczka z sandboksa Groovy i zdalne wykonanie poleceń
CVE-2025-37729CRITICAL9.1PL ✓same vendor
Elastic Cloud Enterprise — Server-Side Template Injection (SSTI) w silniku Jinjava
CVE-2025-25014CRITICAL9.1PL ✓same vendor
Prototype Pollution w Kibana prowadzące do RCE przez HTTP