PT-2019-5288 · Elastic · Kibana

Published

2019-03-25

·

Updated

2019-09-27

·

CVE-2019-7608

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Kibana versions prior to 5.6.15 Kibana versions prior to 6.6.1
Description The issue is related to a lack of protection against cross-site scripting (XSS) attacks, which could allow a remote attacker to perform destructive actions or obtain sensitive information on behalf of other Kibana users.
Recommendations For Kibana versions prior to 5.6.15, update to version 5.6.15 or later. For Kibana versions prior to 6.6.1, update to version 6.6.1 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02208
CVE-2019-7608
RHSA-2019:2860

Affected Products

Kibana