Elastic
Top 10K siteBounty
Program Details
- Handle
- elastic
- Managed
- Yes
Response Metrics
- Response Time
- 9 days
- Bounty Time
- 904 days
- Resolution Time
- 1592 days
Response Efficiency
81%
Scope (61 targets)
web: 33 other: 28 In Scope
- *.ela.st web bounty-eligible
- *.elastic.co web bounty-eligible
- *.elastic.dev web bounty-eligible
- *.elastic.wtf web bounty-eligible
- *.elasticacademy.com web bounty-eligible
- *.elasticaccelerationzone.co web bounty-eligible
- *.elasticapm.co web bounty-eligible
- *.elasticbeats.wtf web bounty-eligible
- *.elasticcloud.wtf web bounty-eligible
- *.elasticgov.com web bounty-eligible
- *.elasticloud.wtf web bounty-eligible
- *.elasticnet.co web bounty-eligible
- *.elasticon.co web bounty-eligible
- *.elasticon.com web bounty-eligible
- *.elasticpartneracademy.com web bounty-eligible
- *.elasticps.co web bounty-eligible
- *.elasticsearch.com web bounty-eligible
- *.elasticsearch.fr web bounty-eligible
- *.elasticsearch.jp web bounty-eligible
- *.elasticsearch.org web bounty-eligible
- and 41 more targets
Out of Scope
*.es.io, *.jina.ai, *.kbndev.co, *.keephq.dev, community.elastic.co, discuss.elastic.co, https://github.com/elastic/*/wiki, https://github.com/swiftype/*/wiki, learn.elastic.co, link.email.elastic.co, sendgrid.elastic.co, track.email.elastic.co
Known Exploited Vulnerabilities 3CVEs
The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.
Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.
Kibana contain an arbitrary code execution flaw in the Timelion visualizer.