Vulnerabilities
Vulnerable Software
Elastic:  >> Kibana  >> 7.14.1.  Security Vulnerabilities
It was discovered that on Windows operating systems specifically, Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host to load internal files ending in the .pbf extension. Thanks to Dominic Couture for finding this vulnerability.
CVSS Score
4.3
EPSS Score
0.003
Published
2021-11-18
It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, which may be intentionally hidden from public view. Using this vulnerability, a malicious user with the ability to create connectors, could utilize these connectors to view limited HTTP response data on hosts accessible to the cluster.
CVSS Score
2.7
EPSS Score
0.002
Published
2021-11-18


Contact Us

Shodan ® - All rights reserved