
CVE-2020-7016
https://notcve.org/view.php?id=CVE-2020-7016
27 Jul 2020 — Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consuming large amounts of CPU and becoming unresponsive. En Kibana versiones anteriores a 6.8.11 y 7.8.1, contiene un fallo de denegación de servicio (DoS) en Timelion. Un atacante puede construir una URL que, cuando es visualizada por un usuario de Kibana, puede conllevar al proceso de Kibana a consumir grandes cantidad... • https://discuss.elastic.co/t/elastic-stack-6-8-11-and-7-8-1-security-update/242786 • CWE-185: Incorrect Regular Expression CWE-400: Uncontrolled Resource Consumption •

CVE-2020-7017
https://notcve.org/view.php?id=CVE-2020-7017
27 Jul 2020 — In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive information or perform destructive actions on behalf of Kibana users who view the region map visualization. En Kibana versiones anteriores a 6.8.11 y 7.8.1, la visualización del mapa de región contiene un fallo de tipo XSS almacenado. Un atacante que es capaz de editar o crear una visualización de mapa de región pod... • https://discuss.elastic.co/t/elastic-stack-6-8-11-and-7-8-1-security-update/242786 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-8444
https://notcve.org/view.php?id=CVE-2017-8444
28 Sep 2017 — The client-forwarder in Elastic Cloud Enterprise versions prior to 1.0.2 do not properly encrypt traffic to ZooKeeper. If an attacker is able to man in the middle (MITM) the traffic between the client-forwarder and ZooKeeper they could potentially obtain sensitive data. client-forwarder en las versiones de Elastic Cloud Enterprise anteriores a 1.0.2 no cifra el tráfico a ZooKeeper. Si un atacante puede realizar un ataque Man-in-the-Middle (MitM) en el tráfico entre client-forwarder y ZooKeeper, podría obten... • https://discuss.elastic.co/t/elastic-cloud-enterprise-1-0-2-security-update/100247 • CWE-319: Cleartext Transmission of Sensitive Information •