Elastic

Kibana

94 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 13.05.2021 18:15:08
  • Zuletzt bearbeitet 21.11.2024 05:49:34

In Kibana versions before 7.12.0 and 6.8.15 a flaw in the session timeout was discovered where the xpack.security.session.idleTimeout setting is not being respected. This was caused by background polling activities unintentionally extending authentic...

  • EPSS 0.17%
  • Veröffentlicht 02.12.2020 01:15:12
  • Zuletzt bearbeitet 21.11.2024 05:21:52

The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it is possible to replace the original openshift-logging console link (kibana console) to different one, created based on the new CR f...

  • EPSS 0.3%
  • Veröffentlicht 03.06.2020 18:15:23
  • Zuletzt bearbeitet 21.11.2024 05:36:29

Kibana versions before 6.8.9 and 7.7.0 contains a stored XSS flaw in the TSVB visualization. An attacker who is able to edit or create a TSVB visualization could allow the attacker to obtain sensitive information from, or perform destructive actions,...

  • EPSS 1.37%
  • Veröffentlicht 03.06.2020 18:15:22
  • Zuletzt bearbeitet 21.11.2024 05:36:29

Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary code. This could possibly lead t...

  • EPSS 73.44%
  • Veröffentlicht 03.06.2020 18:15:22
  • Zuletzt bearbeitet 21.11.2024 05:36:29

Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authenticated attacker with privileges to write to the Kibana index could insert data that would cause Kibana to execute arbitrary code....

  • EPSS 0.35%
  • Veröffentlicht 18.12.2019 20:15:16
  • Zuletzt bearbeitet 21.11.2024 04:48:25

Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with the ability to create coordinate map visualizations could create a malicious visualization. If another ...

  • EPSS 0.21%
  • Veröffentlicht 01.10.2019 18:15:13
  • Zuletzt bearbeitet 21.11.2024 04:48:24

A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is possible to read arbitrary files from the local filesystem of the Kibana instance running Code with th...

  • EPSS 9.09%
  • Veröffentlicht 30.07.2019 22:15:12
  • Zuletzt bearbeitet 21.11.2024 04:48:24

Kibana versions before 6.8.2 and 7.2.1 contain a server side request forgery (SSRF) flaw in the graphite integration for Timelion visualizer. An attacker with administrative Kibana access could set the timelion:graphite.url configuration option to an...

Warnung Exploit
  • EPSS 94.43%
  • Veröffentlicht 25.03.2019 19:29:02
  • Zuletzt bearbeitet 07.11.2025 19:36:46

Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly le...

  • EPSS 0.52%
  • Veröffentlicht 25.03.2019 19:29:02
  • Zuletzt bearbeitet 21.11.2024 04:48:23

Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XSS) vulnerability that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.