CVE-2019-7621
- EPSS 0.35%
- Veröffentlicht 18.12.2019 20:15:16
- Zuletzt bearbeitet 21.11.2024 04:48:25
Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with the ability to create coordinate map visualizations could create a malicious visualization. If another ...
CVE-2019-7618
- EPSS 0.23%
- Veröffentlicht 01.10.2019 18:15:13
- Zuletzt bearbeitet 21.11.2024 04:48:24
A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is possible to read arbitrary files from the local filesystem of the Kibana instance running Code with th...
CVE-2019-7616
- EPSS 9.52%
- Veröffentlicht 30.07.2019 22:15:12
- Zuletzt bearbeitet 21.11.2024 04:48:24
Kibana versions before 6.8.2 and 7.2.1 contain a server side request forgery (SSRF) flaw in the graphite integration for Timelion visualizer. An attacker with administrative Kibana access could set the timelion:graphite.url configuration option to an...
CVE-2019-7610
- EPSS 1.12%
- Veröffentlicht 25.03.2019 19:29:02
- Zuletzt bearbeitet 21.11.2024 04:48:23
Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.security.audit.enabled set to true, an attacker could send a request that will attempt to execute javascrip...
- EPSS 94.42%
- Veröffentlicht 25.03.2019 19:29:02
- Zuletzt bearbeitet 13.03.2025 17:13:50
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly le...
CVE-2019-7608
- EPSS 0.53%
- Veröffentlicht 25.03.2019 19:29:02
- Zuletzt bearbeitet 21.11.2024 04:48:23
Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XSS) vulnerability that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
CVE-2018-17246
- EPSS 93.28%
- Veröffentlicht 20.12.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:54:09
Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code. This could possibly lead to a...
CVE-2018-17245
- EPSS 0.32%
- Veröffentlicht 20.12.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:54:09
Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating PDF reports. If a report requests external resources plaintext credentials are included in the HTTP request tha...
CVE-2018-3830
- EPSS 0.71%
- Veröffentlicht 19.09.2018 19:29:01
- Zuletzt bearbeitet 21.11.2024 04:06:07
Kibana versions 5.3.0 to 6.4.1 had a cross-site scripting (XSS) vulnerability via the source field formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
CVE-2018-3821
- EPSS 0.38%
- Veröffentlicht 30.03.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:06:06
Kibana versions after 5.1.1 and before 5.6.7 and 6.1.3 had a cross-site scripting (XSS) vulnerability in the tag cloud visualization that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other K...