Elastic

Kibana

101 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 10.10.2025 09:53:25
  • Zuletzt bearbeitet 30.10.2025 14:29:18

Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS)

  • EPSS 0.03%
  • Veröffentlicht 10.10.2025 09:50:35
  • Zuletzt bearbeitet 30.10.2025 14:25:55

Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)

  • EPSS 0.02%
  • Veröffentlicht 07.10.2025 13:59:00
  • Zuletzt bearbeitet 30.10.2025 14:47:00

Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload.

  • EPSS 0.03%
  • Veröffentlicht 07.10.2025 13:54:49
  • Zuletzt bearbeitet 08.10.2025 19:38:32

Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A malicious user can access cached credentials from a Crowdstrike connector in another space by creating and running a Crowdstrike con...

  • EPSS 0.04%
  • Veröffentlicht 28.08.2025 15:52:08
  • Zuletzt bearbeitet 01.10.2025 18:45:24

Incorrect authorization in Kibana can lead to privilege escalation via the built-in reporting_user role which incorrectly has the ability to access all Kibana Spaces.

  • EPSS 0.07%
  • Veröffentlicht 25.06.2025 11:52:53
  • Zuletzt bearbeitet 30.09.2025 20:27:39

URL redirection to an untrusted site ('Open Redirect') in Kibana can lead to sending a user to an arbitrary site and server-side request forgery via a specially crafted URL.

  • EPSS 0.09%
  • Veröffentlicht 10.06.2025 16:59:54
  • Zuletzt bearbeitet 01.10.2025 15:27:00

Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a Synthetic monitor endpoint.

  • EPSS 2.54%
  • Veröffentlicht 06.05.2025 17:30:45
  • Zuletzt bearbeitet 02.10.2025 16:26:53

A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.

  • EPSS 0.27%
  • Veröffentlicht 01.05.2025 13:11:14
  • Zuletzt bearbeitet 01.10.2025 19:29:57

Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s browser (XSS) via crafted HTML and JavaScript files. The attacker must have access to the Synthetics app AND/OR have access to write...

  • EPSS 0.19%
  • Veröffentlicht 01.05.2025 13:09:16
  • Zuletzt bearbeitet 02.10.2025 16:34:04

Unrestricted file upload in Kibana allows an authenticated attacker to compromise software integrity by uploading a crafted malicious file due to insufficient server-side validation.