6.7
CVE-2020-7017
- EPSS 0.92%
- Published 27.07.2020 18:15:14
- Last modified 21.11.2024 05:36:30
- Source bressers@elastic.co
- Teams watchlist Login
- Open Login
In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive information or perform destructive actions on behalf of Kibana users who view the region map visualization.
Data is provided by the National Vulnerability Database (NVD)
Elasticsearch ≫ Kibana Version < 6.8.11
Elasticsearch ≫ Kibana Version >= 7.0.0 < 7.8.1
Oracle ≫ Communications Billing And Revenue Management Version12.0.0.3.0
Oracle ≫ Peoplesoft Enterprise Peopletools Version8.58
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.92% | 0.738 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.7 | 1.2 | 5.5 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L
|
nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:N/AC:H/Au:S/C:P/I:P/A:P
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.