Skip to main content

Vendor/product archive

elastic / elastic_app_search CVEs

Beta · best-effort

2 CVEs tagged to elastic / elastic_app_search0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2021-22140

Published May 13, 2021

Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta feature. Using this vector, an a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7011

Published Jun 3, 2020

Elastic App Search versions before 7.7.0 contain a cross site scripting (XSS) flaw when displaying document URLs in the Reference UI. If the Reference UI injects a URL into a resu…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1