Elastic

Kibana

101 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 73.44%
  • Veröffentlicht 03.06.2020 18:15:22
  • Zuletzt bearbeitet 21.11.2024 05:36:29

Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authenticated attacker with privileges to write to the Kibana index could insert data that would cause Kibana to execute arbitrary code....

  • EPSS 1.37%
  • Veröffentlicht 03.06.2020 18:15:22
  • Zuletzt bearbeitet 21.11.2024 05:36:29

Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary code. This could possibly lead t...

  • EPSS 0.35%
  • Veröffentlicht 18.12.2019 20:15:16
  • Zuletzt bearbeitet 21.11.2024 04:48:25

Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with the ability to create coordinate map visualizations could create a malicious visualization. If another ...

  • EPSS 0.21%
  • Veröffentlicht 01.10.2019 18:15:13
  • Zuletzt bearbeitet 21.11.2024 04:48:24

A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is possible to read arbitrary files from the local filesystem of the Kibana instance running Code with th...

  • EPSS 9.09%
  • Veröffentlicht 30.07.2019 22:15:12
  • Zuletzt bearbeitet 21.11.2024 04:48:24

Kibana versions before 6.8.2 and 7.2.1 contain a server side request forgery (SSRF) flaw in the graphite integration for Timelion visualizer. An attacker with administrative Kibana access could set the timelion:graphite.url configuration option to an...

  • EPSS 0.5%
  • Veröffentlicht 25.03.2019 19:29:02
  • Zuletzt bearbeitet 21.11.2024 04:48:23

Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XSS) vulnerability that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

Warnung Exploit
  • EPSS 94.43%
  • Veröffentlicht 25.03.2019 19:29:02
  • Zuletzt bearbeitet 07.11.2025 19:36:46

Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly le...

  • EPSS 1.06%
  • Veröffentlicht 25.03.2019 19:29:02
  • Zuletzt bearbeitet 21.11.2024 04:48:23

Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.security.audit.enabled set to true, an attacker could send a request that will attempt to execute javascrip...

  • EPSS 0.32%
  • Veröffentlicht 20.12.2018 22:29:00
  • Zuletzt bearbeitet 21.11.2024 03:54:09

Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating PDF reports. If a report requests external resources plaintext credentials are included in the HTTP request tha...

  • EPSS 93.78%
  • Veröffentlicht 20.12.2018 22:29:00
  • Zuletzt bearbeitet 21.11.2024 03:54:09

Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code. This could possibly lead to a...