Important: Elastic Stack security update
NetEye Product Security has rated this update as having a High security impact.
Updates for the Elastic Stack packages are now available for NetEye 4.
9.4.5_neteye3.103.7-1Elasticsearch
Fleet Server
Kibana
Most of the 36 CVEs are Denial of Service vulnerabilities affecting Elasticsearch (uncontrolled recursion in intervals queries/wildcard matching/analysis definitions, memory allocation without limits in search/highlighting) and Kibana (TSVB, connector reporting, alerting, case management, Observability log analysis, CSRF via Vega visualizations), within the Elastic Stack. The remaining CVEs relate to authorization and access control weaknesses in Kibana and Fleet Server, including Missing/Incorrect Authorization (Agent Builder privilege escalation and data tampering, Elastic Defend endpoint response actions information disclosure, cross-space access to Machine Learning trained models, unauthorized execution of Osquery/Endpoint response actions), Authorization Bypass Through User-Controlled Key (Fleet Elastic Agent API key disclosure, cross-space alerting telemetry and ML disclosure), Code Injection in Fleet Server, and an Out-of-range Pointer Offset in the Elasticsearch Machine Learning native inference process, that can lead to unauthorized information disclosure, privilege escalation, data tampering or remote code execution.
All NetEye 4.x versions >= 4.31.