Elastic

Kibana

94 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 15.12.2025 10:21:07
  • Zuletzt bearbeitet 18.12.2025 01:45:36

Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to render HTML tags within a user’s browser via the integration package upload functionality. This issue is related to ESA-2025...

  • EPSS 0.02%
  • Veröffentlicht 12.11.2025 09:57:22
  • Zuletzt bearbeitet 11.12.2025 21:09:00

Origin Validation Error in Kibana can lead to Server-Side Request Forgery via a forged Origin HTTP header processed by the Observability AI Assistant.

  • EPSS 0.02%
  • Veröffentlicht 06.11.2025 14:27:26
  • Zuletzt bearbeitet 06.11.2025 19:45:09

Improper preservation of permissions in Elastic Defend on Windows hosts can lead to arbitrary files on the system being deleted by the Defend service running as SYSTEM. In some cases, this could result in local privilege escalation.

  • EPSS 0.04%
  • Veröffentlicht 10.10.2025 09:53:25
  • Zuletzt bearbeitet 30.10.2025 14:29:18

Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS)

  • EPSS 0.04%
  • Veröffentlicht 10.10.2025 09:50:35
  • Zuletzt bearbeitet 30.10.2025 14:25:55

Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)

  • EPSS 0.04%
  • Veröffentlicht 07.10.2025 13:59:00
  • Zuletzt bearbeitet 30.10.2025 14:47:00

Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload.

  • EPSS 0.03%
  • Veröffentlicht 07.10.2025 13:54:49
  • Zuletzt bearbeitet 08.10.2025 19:38:32

Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A malicious user can access cached credentials from a Crowdstrike connector in another space by creating and running a Crowdstrike con...

  • EPSS 0.03%
  • Veröffentlicht 28.08.2025 15:52:08
  • Zuletzt bearbeitet 01.10.2025 18:45:24

Incorrect authorization in Kibana can lead to privilege escalation via the built-in reporting_user role which incorrectly has the ability to access all Kibana Spaces.

  • EPSS 0.06%
  • Veröffentlicht 25.06.2025 11:52:53
  • Zuletzt bearbeitet 30.09.2025 20:27:39

URL redirection to an untrusted site ('Open Redirect') in Kibana can lead to sending a user to an arbitrary site and server-side request forgery via a specially crafted URL.

  • EPSS 0.06%
  • Veröffentlicht 10.06.2025 16:59:54
  • Zuletzt bearbeitet 01.10.2025 15:27:00

Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a Synthetic monitor endpoint.