Elastic

Elastic

Top 10K site
Bounty

Program Details

Handle
elastic
Managed
Yes

Response Metrics

Response Time
8 days
Bounty Time
1046 days
Resolution Time
2006 days
Response Efficiency
82%

Scope (35 targets)

web: 31 other: 4

Bounty splitting: Yes

In Scope

  • *.ela.st web bounty-eligible
  • *.elastic.co web bounty-eligible
  • *.elastic.dev web bounty-eligible
  • *.elastic.wtf web bounty-eligible
  • *.elasticacademy.com web bounty-eligible
  • *.elasticaccelerationzone.co web bounty-eligible
  • *.elasticapm.co web bounty-eligible
  • *.elasticbeats.wtf web bounty-eligible
  • *.elasticcloud.wtf web bounty-eligible
  • *.elasticgov.com web bounty-eligible
  • *.elasticloud.wtf web bounty-eligible
  • *.elasticnet.co web bounty-eligible
  • *.elasticon.co web bounty-eligible
  • *.elasticon.com web bounty-eligible
  • *.elasticpartneracademy.com web bounty-eligible
  • *.elasticps.co web bounty-eligible
  • *.elasticsearch.com web bounty-eligible
  • *.elasticsearch.fr web bounty-eligible
  • *.elasticsearch.jp web bounty-eligible
  • *.elasticsearch.org web bounty-eligible
  • and 15 more targets

Out of Scope

*.es.io, *.jina.ai, *.kbndev.co, *.keephq.dev, *.swiftype.com, Beats, Beats - Auditbeat, Beats - Filebeat, Beats - Heartbeat, Beats - Metricbeat, Beats - Osquerybeat, Beats - Packetbeat, Beats - Winlogbeat, Elastic Agent, Elastic Clients, Elastic Cloud Enterprise (ECE), Elastic Cloud on Kubernetes (ECK), Elastic Defend, Elastic Distributions of OpenTelemetry (EDOT), Elastic Enterprise Search, Elastic Maps Server, Elastic Package Registry, Elastic Synthetics Monitoring, Elasticsearch, Fleet Server, Kibana, Logstash, Observability - APM Agents, Observability - APM Server, cloud.elastic.co, community.elastic.co, discuss.elastic.co, https://github.com/elastic/*/wiki, https://github.com/swiftype/*/wiki, learn.elastic.co, link.email.elastic.co, sendgrid.elastic.co, track.email.elastic.co

Known Exploited Vulnerabilities 3CVEs

  • CVE-2015-1427ElasticsearchMar 25, 202299.9% EPSS

    The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.

  • CVE-2014-3120ElasticsearchMar 25, 202288.6% EPSS

    Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.

  • CVE-2019-7609KibanaJan 10, 202295.3% EPSS

    Kibana contain an arbitrary code execution flaw in the Timelion visualizer.