PT-2022-2373 · Elastic · Kibana

Brian Levine

·

Published

2022-01-19

·

Updated

2022-05-03

·

CVE-2022-23711

CVSS v2.0

6.8

Medium

VectorAV:A/AC:L/Au:N/C:C/I:P/A:N
Name of the Vulnerable Software and Affected Versions Kibana (affected versions not specified)
Description A vulnerability in Kibana is related to the exposure of information. Exploitation of this issue may allow a remote attacker to disclose protected information. The vulnerability can expose sensitive information related to Elastic Stack monitoring in the Kibana page source. This exposure only impacts users who have set any of the optional monitoring.ui.elasticsearch.* settings to configure Kibana as a remote UI for Elastic Stack Monitoring. No authentication with a vulnerable Kibana instance is required to view the exposed information. The vulnerability can also expose other non-sensitive application-internal information in the page source.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02725
CVE-2022-23711

Affected Products

Kibana