Multiple Vulnerabilities Discovered in Elastic Products

The CERT-FR has issued a warning that several vulnerabilities have been identified in Elastic products, enabling remote attackers to cause denial‑of‑service, breach data confidentiality, and compromise data integrity. Affected versions include Elastic Defend 9.3.x before 9.3.2, 9.x before 9.2.7, and 8.6.x‑8.19.13; Elasticsearch 7.x before 7.17.24, 8.x before 8.19.17, 9.4.x before 9.4.3, and 9.x before 9.3.5; Fleet Server 8.x before 8.19.15 and 9.x before 9.3.4; and Kibana 7.x before 7.17.15, 8.17.x before 8.17.2, 8.18.x before 8.18.9, 8.19.x before 8.19.17, 8.x before 8.16.3, and 9.x before 9.0.8, 9.1.6, 9.3.6 or 9.4.3. Users are advised to apply the patches provided in Elastic’s security bulletins, which are referenced in the CERT-FR notice.

Summary of content from

source

Made by AI. If you spot anything of concern write us at contact@cybach.com. We’ll promptly correct irregularities.


Posted