Elastic

Elastic

Top 10K site
Bounty

Program Details

Handle
elastic
Managed
Yes

Response Metrics

Response Time
9 days
Bounty Time
904 days
Resolution Time
1592 days
Response Efficiency
81%

Scope (61 targets)

web: 33 other: 28

Bounty splitting: Yes

In Scope

  • *.ela.st web bounty-eligible
  • *.elastic.co web bounty-eligible
  • *.elastic.dev web bounty-eligible
  • *.elastic.wtf web bounty-eligible
  • *.elasticacademy.com web bounty-eligible
  • *.elasticaccelerationzone.co web bounty-eligible
  • *.elasticapm.co web bounty-eligible
  • *.elasticbeats.wtf web bounty-eligible
  • *.elasticcloud.wtf web bounty-eligible
  • *.elasticgov.com web bounty-eligible
  • *.elasticloud.wtf web bounty-eligible
  • *.elasticnet.co web bounty-eligible
  • *.elasticon.co web bounty-eligible
  • *.elasticon.com web bounty-eligible
  • *.elasticpartneracademy.com web bounty-eligible
  • *.elasticps.co web bounty-eligible
  • *.elasticsearch.com web bounty-eligible
  • *.elasticsearch.fr web bounty-eligible
  • *.elasticsearch.jp web bounty-eligible
  • *.elasticsearch.org web bounty-eligible
  • and 41 more targets

Out of Scope

*.es.io, *.jina.ai, *.kbndev.co, *.keephq.dev, community.elastic.co, discuss.elastic.co, https://github.com/elastic/*/wiki, https://github.com/swiftype/*/wiki, learn.elastic.co, link.email.elastic.co, sendgrid.elastic.co, track.email.elastic.co

Known Exploited Vulnerabilities 3CVEs

  • CVE-2015-1427ElasticsearchMar 25, 202299.9% EPSS

    The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.

  • CVE-2014-3120ElasticsearchMar 25, 202288.6% EPSS

    Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.

  • CVE-2019-7609KibanaJan 10, 202295.3% EPSS

    Kibana contain an arbitrary code execution flaw in the Timelion visualizer.