PT-2022-10685 · Elastic · Kibana

Published

2022-11-18

·

Updated

2025-04-29

·

CVE-2021-37936

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kibana (affected versions not specified)
Description It was discovered that Kibana was not sanitizing document fields containing HTML snippets. An attacker with the ability to write documents to an Elasticsearch index could inject HTML. When the Discover app highlighted a search term containing the HTML, it would be rendered for the user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-37936

Affected Products

Kibana