Elastic
Top 10K siteProgram Details
- Handle
- elastic
- Managed
- Yes
Response Metrics
- Response Time
- 8 days
- Bounty Time
- 1046 days
- Resolution Time
- 2006 days
Scope (35 targets)
web: 31 other: 4 In Scope
- *.ela.st web bounty-eligible
- *.elastic.co web bounty-eligible
- *.elastic.dev web bounty-eligible
- *.elastic.wtf web bounty-eligible
- *.elasticacademy.com web bounty-eligible
- *.elasticaccelerationzone.co web bounty-eligible
- *.elasticapm.co web bounty-eligible
- *.elasticbeats.wtf web bounty-eligible
- *.elasticcloud.wtf web bounty-eligible
- *.elasticgov.com web bounty-eligible
- *.elasticloud.wtf web bounty-eligible
- *.elasticnet.co web bounty-eligible
- *.elasticon.co web bounty-eligible
- *.elasticon.com web bounty-eligible
- *.elasticpartneracademy.com web bounty-eligible
- *.elasticps.co web bounty-eligible
- *.elasticsearch.com web bounty-eligible
- *.elasticsearch.fr web bounty-eligible
- *.elasticsearch.jp web bounty-eligible
- *.elasticsearch.org web bounty-eligible
- and 15 more targets
Out of Scope
*.es.io, *.jina.ai, *.kbndev.co, *.keephq.dev, *.swiftype.com, Beats, Beats - Auditbeat, Beats - Filebeat, Beats - Heartbeat, Beats - Metricbeat, Beats - Osquerybeat, Beats - Packetbeat, Beats - Winlogbeat, Elastic Agent, Elastic Clients, Elastic Cloud Enterprise (ECE), Elastic Cloud on Kubernetes (ECK), Elastic Defend, Elastic Distributions of OpenTelemetry (EDOT), Elastic Enterprise Search, Elastic Maps Server, Elastic Package Registry, Elastic Synthetics Monitoring, Elasticsearch, Fleet Server, Kibana, Logstash, Observability - APM Agents, Observability - APM Server, cloud.elastic.co, community.elastic.co, discuss.elastic.co, https://github.com/elastic/*/wiki, https://github.com/swiftype/*/wiki, learn.elastic.co, link.email.elastic.co, sendgrid.elastic.co, track.email.elastic.co
Known Exploited Vulnerabilities 3CVEs
The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.
Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.
Kibana contain an arbitrary code execution flaw in the Timelion visualizer.