PT-2025-18389 · Elastic · Kibana

Published

2025-05-01

·

Updated

2025-05-05

·

CVE-2024-11390

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kibana (affected versions not specified)
Description The issue allows for the unrestricted upload of files with dangerous types, potentially leading to arbitrary JavaScript execution in a victim's browser, resulting in a cross-site scripting (XSS) attack. This can be achieved via crafted HTML and JavaScript files. The attacker must have access to the Synthetics app and/or have write access to the synthetics indices.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BIT-ELK-2024-11390
BIT-KIBANA-2024-11390
CVE-2024-11390

Affected Products

Kibana