PT-2022-2373 · Elastic · Kibana
Brian Levine
·
Published
2022-01-19
·
Updated
2022-05-03
·
CVE-2022-23711
CVSS v2.0
6.8
Medium
| Vector | AV:A/AC:L/Au:N/C:C/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Kibana (affected versions not specified)
Description
A vulnerability in Kibana is related to the exposure of information. Exploitation of this issue may allow a remote attacker to disclose protected information. The vulnerability can expose sensitive information related to Elastic Stack monitoring in the Kibana page source. This exposure only impacts users who have set any of the optional
monitoring.ui.elasticsearch.* settings to configure Kibana as a remote UI for Elastic Stack Monitoring. No authentication with a vulnerable Kibana instance is required to view the exposed information. The vulnerability can also expose other non-sensitive application-internal information in the page source.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kibana