Elastic

Kibana

83 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 12.11.2025 09:57:22
  • Zuletzt bearbeitet 12.11.2025 16:19:12

Origin Validation Error in Kibana can lead to Server-Side Request Forgery via a forged Origin HTTP header processed by the Observability AI Assistant.

  • EPSS 0.01%
  • Veröffentlicht 06.11.2025 14:27:26
  • Zuletzt bearbeitet 06.11.2025 19:45:09

Improper preservation of permissions in Elastic Defend on Windows hosts can lead to arbitrary files on the system being deleted by the Defend service running as SYSTEM. In some cases, this could result in local privilege escalation.

  • EPSS 0.04%
  • Veröffentlicht 10.10.2025 09:53:25
  • Zuletzt bearbeitet 30.10.2025 14:29:18

Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS)

  • EPSS 0.04%
  • Veröffentlicht 10.10.2025 09:50:35
  • Zuletzt bearbeitet 30.10.2025 14:25:55

Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)

  • EPSS 0.04%
  • Veröffentlicht 07.10.2025 13:59:00
  • Zuletzt bearbeitet 30.10.2025 14:47:00

Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload.

  • EPSS 0.03%
  • Veröffentlicht 07.10.2025 13:54:49
  • Zuletzt bearbeitet 08.10.2025 19:38:32

Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A malicious user can access cached credentials from a Crowdstrike connector in another space by creating and running a Crowdstrike con...

  • EPSS 0.04%
  • Veröffentlicht 28.08.2025 15:52:08
  • Zuletzt bearbeitet 01.10.2025 18:45:24

Incorrect authorization in Kibana can lead to privilege escalation via the built-in reporting_user role which incorrectly has the ability to access all Kibana Spaces.

  • EPSS 0.05%
  • Veröffentlicht 25.06.2025 11:52:53
  • Zuletzt bearbeitet 30.09.2025 20:27:39

URL redirection to an untrusted site ('Open Redirect') in Kibana can lead to sending a user to an arbitrary site and server-side request forgery via a specially crafted URL.

  • EPSS 0.06%
  • Veröffentlicht 10.06.2025 16:59:54
  • Zuletzt bearbeitet 01.10.2025 15:27:00

Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a Synthetic monitor endpoint.

  • EPSS 0.92%
  • Veröffentlicht 06.05.2025 17:30:45
  • Zuletzt bearbeitet 02.10.2025 16:26:53

A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.