PT-2022-16217 · Elastic · Kibana

Published

2022-02-11

·

Updated

2022-02-22

·

CVE-2022-23707

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kibana (affected versions not specified)
Description A Cross-Site Scripting (XSS) issue was discovered in Kibana index patterns. This issue allows an authenticated user with permissions to create index patterns to inject malicious JavaScript into the index pattern, which could then execute against other users.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23707

Affected Products

Kibana