Elastic

Kibana

106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 18.12.2025 22:11:39
  • Zuletzt bearbeitet 23.12.2025 19:07:16

Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an unauthenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via ...

  • EPSS 0.02%
  • Veröffentlicht 18.12.2025 22:08:37
  • Zuletzt bearbeitet 23.12.2025 19:07:09

Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via a ...

  • EPSS 0.02%
  • Veröffentlicht 15.12.2025 10:21:07
  • Zuletzt bearbeitet 18.12.2025 01:45:36

Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to render HTML tags within a user’s browser via the integration package upload functionality. This issue is related to ESA-2025...

  • EPSS 0.02%
  • Veröffentlicht 12.11.2025 09:57:22
  • Zuletzt bearbeitet 11.12.2025 21:09:00

Origin Validation Error in Kibana can lead to Server-Side Request Forgery via a forged Origin HTTP header processed by the Observability AI Assistant.

  • EPSS 0.01%
  • Veröffentlicht 06.11.2025 14:27:26
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Improper preservation of permissions in Elastic Defend on Windows hosts can lead to arbitrary files on the system being deleted by the Defend service running as SYSTEM. In some cases, this could result in local privilege escalation.

  • EPSS 0.03%
  • Veröffentlicht 10.10.2025 09:53:25
  • Zuletzt bearbeitet 30.10.2025 14:29:18

Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS)

  • EPSS 0.03%
  • Veröffentlicht 10.10.2025 09:50:35
  • Zuletzt bearbeitet 30.10.2025 14:25:55

Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)

  • EPSS 0.02%
  • Veröffentlicht 07.10.2025 13:59:00
  • Zuletzt bearbeitet 30.10.2025 14:47:00

Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload.

  • EPSS 0.03%
  • Veröffentlicht 07.10.2025 13:54:49
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A malicious user can access cached credentials from a Crowdstrike connector in another space by creating and running a Crowdstrike con...

  • EPSS 0.04%
  • Veröffentlicht 28.08.2025 15:52:08
  • Zuletzt bearbeitet 01.10.2025 18:45:24

Incorrect authorization in Kibana can lead to privilege escalation via the built-in reporting_user role which incorrectly has the ability to access all Kibana Spaces.