The Elsa Project maintains a narrowly scoped log aggregation and analysis platform, with vulnerability disclosures clustering around its core product and centered on web-facing input-handling weaknesses such as cross-site scripting. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Elsa Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-1223HIGH The web administration server for ELSA Lancom 1100 Office does not require authentication, which allows arbitrary remote attackers to gain administrative privileges by connecting t | Dec 26, 2001 | 10.0 | 25 | NO | NO |
CVE-2018-1000029MEDIUM mcholste Enterprise Log Search and Archive (ELSA) version revision 1205, commit 2cc17f1 and earlier contains a Cross Site Scripting (XSS) vulnerability in index view (/) that can r | Feb 9, 2018 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Elsa Project.
Media articles that mention a CVE ID that affects a product developed by Elsa Project — matched by CVE ID, not by vendor name.