Elastic

Kibana

83 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Veröffentlicht 02.12.2020 01:15:12
  • Zuletzt bearbeitet 21.11.2024 05:21:52

The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it is possible to replace the original openshift-logging console link (kibana console) to different one, created based on the new CR f...

  • EPSS 0.4%
  • Veröffentlicht 03.06.2020 18:15:23
  • Zuletzt bearbeitet 21.11.2024 05:36:29

Kibana versions before 6.8.9 and 7.7.0 contains a stored XSS flaw in the TSVB visualization. An attacker who is able to edit or create a TSVB visualization could allow the attacker to obtain sensitive information from, or perform destructive actions,...

  • EPSS 1.14%
  • Veröffentlicht 03.06.2020 18:15:22
  • Zuletzt bearbeitet 21.11.2024 05:36:29

Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary code. This could possibly lead t...

  • EPSS 73.44%
  • Veröffentlicht 03.06.2020 18:15:22
  • Zuletzt bearbeitet 21.11.2024 05:36:29

Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authenticated attacker with privileges to write to the Kibana index could insert data that would cause Kibana to execute arbitrary code....

  • EPSS 0.35%
  • Veröffentlicht 18.12.2019 20:15:16
  • Zuletzt bearbeitet 21.11.2024 04:48:25

Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with the ability to create coordinate map visualizations could create a malicious visualization. If another ...

  • EPSS 0.23%
  • Veröffentlicht 01.10.2019 18:15:13
  • Zuletzt bearbeitet 21.11.2024 04:48:24

A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is possible to read arbitrary files from the local filesystem of the Kibana instance running Code with th...

  • EPSS 9.09%
  • Veröffentlicht 30.07.2019 22:15:12
  • Zuletzt bearbeitet 21.11.2024 04:48:24

Kibana versions before 6.8.2 and 7.2.1 contain a server side request forgery (SSRF) flaw in the graphite integration for Timelion visualizer. An attacker with administrative Kibana access could set the timelion:graphite.url configuration option to an...

  • EPSS 1.12%
  • Veröffentlicht 25.03.2019 19:29:02
  • Zuletzt bearbeitet 21.11.2024 04:48:23

Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.security.audit.enabled set to true, an attacker could send a request that will attempt to execute javascrip...

Warnung Exploit
  • EPSS 94.45%
  • Veröffentlicht 25.03.2019 19:29:02
  • Zuletzt bearbeitet 07.11.2025 19:36:46

Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly le...

  • EPSS 0.53%
  • Veröffentlicht 25.03.2019 19:29:02
  • Zuletzt bearbeitet 21.11.2024 04:48:23

Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XSS) vulnerability that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.