CVE-2021-22140
Published May 13, 2021Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta feature. Using this vector, an a…
Vendor/product archive
2 CVEs tagged to elastic / elastic_app_search — 0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.
Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta feature. Using this vector, an a…
Elastic App Search versions before 7.7.0 contain a cross site scripting (XSS) flaw when displaying document URLs in the Reference UI. If the Reference UI injects a URL into a resu…