Known vulnerabilities in Elastic Cloud Enterprise
Vendor:
Elastic Stack
Software:
Elastic Cloud Enterprise
Software CPE:
cpe:2.3:a:elastic_stack:elastic_cloud_enterprise:*:*:*:*:*:*:*:*
Website:
https://www.elastic.co/
Total vulnerabilities:
5
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
3.8.4
4.0.3
3.8.3
4.0.2
4.0.1
4.0.0
3.8.2
3.8.1
3.8.0
3.7.3
3.7.2
3.7.1
3.7.0
3.6.2
2.13.4
3.6.1
3.6.0
3.5.1
3.5.0
3.4.1
3.4.0
3.3.0
3.2.1
3.2.0
3.1.1
3.1.0
3.0.0
2.13.3
2.13.2
2.13.1
2.13.0
2.12.4
2.12.3
2.12.2
2.12.1
2.12.0
2.11.2
2.11.1
2.11.0
2.10.1
2.10.0
2.9.2
2.9.1
2.9.0
2.8.1
2.8.0
2.7.2
2.7.1
2.7.0
2.6.2
2.6.1
2.6.0
2.5.1
2.5.0
2.4.3
2.4.2
2.4.1
2.4.0
2.3.2
2.3.1
2.3.0
2.2.3
2.2.2
2.2.1
2.2.0
2.1.1
2.1.0
2.0.1
2.0.0
1.1.5
1.1.4
1.1.3
1.1.2
1.1.1
1.1.0
1.0.2
1.0.1
1.0.0
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU117887 - Improper Authorization CVE-2025-37736 |
CWE-285 | Medium | 3.8.3, 4.0.3 | 01.11.2025 |
SB2025110108 |
||
| #VU116965 - Improper Control of Generation of Code ('Code Injection') CVE-2025-37729 |
CWE-94 | Low | 3.8.2, 4.0.2 | 13.10.2025 |
SB20251013102 |
||
| #VU93482 - Improper Authorization CVE-2024-37282 |
CWE-285 | Medium | 3.7.2 | 28.06.2024 |
SB2024062822 |
||
| #VU81073 - Resource exhaustion CVE-2023-31418 |
CWE-400 | Medium | 2.13.4, 3.6.1 | 22.09.2023 |
SB2023092233 SB2024020704 SB2024071610 and 2 more |
||
| #VU75044 - Uncontrolled Recursion CVE-2023-1370 |
CWE-674 | Medium | 2.13.3, 3.3.0 | 12.04.2023 |
SB2023041258 SB2023041259 SB2023041809 and 130 more |