Vulnerabilities
Vulnerable Software
Elastic:  >> Kibana  >> 7.15.1  Security Vulnerabilities
An XSS vulnerability was found in Kibana index patterns. Using this vulnerability, an authenticated user with permissions to create index patterns can inject malicious javascript into the index pattern which could execute against other users
CVSS Score
5.4
EPSS Score
0.005
Published
2022-02-11
It was discovered that on Windows operating systems specifically, Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host to load internal files ending in the .pbf extension. Thanks to Dominic Couture for finding this vulnerability.
CVSS Score
4.3
EPSS Score
0.003
Published
2021-11-18
It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, which may be intentionally hidden from public view. Using this vulnerability, a malicious user with the ability to create connectors, could utilize these connectors to view limited HTTP response data on hosts accessible to the cluster.
CVSS Score
2.7
EPSS Score
0.002
Published
2021-11-18


Contact Us

Shodan ® - All rights reserved