PT-2018-16224 · Elastic · Kibana

Published

2018-09-19

·

Updated

2023-03-03

·

CVE-2018-3830

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kibana versions 5.3.0 through 6.4.1
Description A cross-site scripting (XSS) issue was found in the source field formatter, allowing an attacker to obtain sensitive information or perform actions on behalf of other users.
Recommendations For versions 5.3.0 through 6.4.1, update to a version that contains a fix for this issue to prevent cross-site scripting attacks.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2018-3830
RHSA-2018:3537

Affected Products

Kibana