Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY89 SECURITY RECORDS

Elastic

elasticsearch

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This CVE identity is linked to the Lifecycle record Elasticsearch. Use that record for publisher support phases and retirement dates.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2024-52980 8 Apr 2025 7.17.0 ≤ 8.15.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2024-43709 21 Jan 2025 7.17.0, 8.0.0 < 7.17.21, 8.13.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2024-12539 17 Dec 2024 8.16.0 ≤ 8.16.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2024-23444 31 Jul 2024 7.x < 7.17.23; 8.x < 8.13.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-49921 26 Jul 2024 7.0.0 < 7.17.16; 8.0.0 < 8.11.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2024-37280 13 Jun 2024 8.13.1 ≤ 8.13.4 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2024-23445 12 Jun 2024 8.10.0 < 8.14.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2024-23449 29 Mar 2024 8.4.0 < 8.11.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2024-23451 27 Mar 2024 8.10.0 < 8.13.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2024-23450 27 Mar 2024 7.0.0 < 7.17.19; 8.0.0 < 8.13.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-46673 22 Nov 2023 7.0.0 < 7.17.14; 8.0.0 < 8.10.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2021-37937 22 Nov 2023 7.13.0 < 7.14.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-31417 26 Oct 2023 7.0.0 < 7.17.12; 8.0.0 < 8.9.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-31418 26 Oct 2023 7.17.12; 8.0.0 < 8.8.2; 2.13.3 < 3.6.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-31419 26 Oct 2023 7.0.0 < 7.17.12; 8.0.0 < 8.9.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-23712 6 Jun 2022 versions 8.0.0 through 8.2.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-23708 3 Mar 2022 Versions 7.16.0 through 7.17.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2021-22147 15 Sep 2021 versions 7.11.0 to 7.13.4 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2021-22145 21 Jul 2021 7.10.0 ≤ 7.13.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2021-22138 13 May 2021 after 6.4.0 and before 6.8.15 and 7.12.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2021-22137 13 May 2021 before 7.11.2 and 6.8.15 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2021-22135 13 May 2021 before 7.11.2 and 6.8.15 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2021-22134 8 Mar 2021 after 7.6.0 and before 7.11.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2020-7021 10 Feb 2021 before 7.10.0 and 6.8.14 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2021-22132 14 Jan 2021 7.7.0 to 7.10.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2020-7020 22 Oct 2020 before 6.8.13 and 7.9.2 Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Installation instructions are available from the Fuse 7.11.0 product documentation page: https://access.redhat.com/documentation/en-us/red_hat_fuse/7.11/ Update reference ↗
CVE-2020-7019 18 Aug 2020 before 7.9.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2020-7014 3 Jun 2020 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2020-7009 31 Mar 2020 All versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2019-7619 30 Oct 2019 7.0.0, 7.0.1, 7.1.0, 7.1.1, 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.3.2, 6.7.0, 6.7.1, 6.7.2, 6.8.0, 6.8.1, 6.8.2, 6.8.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2019-7614 30 Jul 2019 before 7.2.1 and 6.8.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2019-7611 25 Mar 2019 before 5.6.15 and 6.6.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2018-17247 20 Dec 2018 6.5.0 and 6.5.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2018-17244 20 Dec 2018 6.4.0 to 6.4.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2018-3831 19 Sep 2018 before 5.6.12 and 6.4.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2018-3827 19 Sep 2018 before 6.3.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2018-3826 19 Sep 2018 6.0.0-beta1 to 6.2.4 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2015-1427 17 Feb 2015 n/a An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2014-3120 28 Jul 2014 n/a No fixed version is explicitly recorded in the structured CVE data. Use CVE record

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.