Show filters
74 Total Results
Displaying 41-50 of 74
Sort by:
Attacker Value
Unknown

CVE-2020-7015

Disclosure Date: June 03, 2020 (last updated February 21, 2025)
Kibana versions before 6.8.9 and 7.7.0 contains a stored XSS flaw in the TSVB visualization. An attacker who is able to edit or create a TSVB visualization could allow the attacker to obtain sensitive information from, or perform destructive actions, on behalf of Kibana users who edit the TSVB visualization.
Attacker Value
Unknown

CVE-2020-7012

Disclosure Date: June 03, 2020 (last updated February 21, 2025)
Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authenticated attacker with privileges to write to the Kibana index could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana process on the host system.
Attacker Value
Unknown

CVE-2020-7013

Disclosure Date: June 03, 2020 (last updated February 21, 2025)
Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana process on the host system.
Attacker Value
Unknown

CVE-2019-7621

Disclosure Date: December 18, 2019 (last updated November 27, 2024)
Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with the ability to create coordinate map visualizations could create a malicious visualization. If another Kibana user views that visualization or a dashboard containing the visualization it could execute JavaScript in the victim�s browser.
Attacker Value
Unknown

CVE-2019-7618

Disclosure Date: October 01, 2019 (last updated November 27, 2024)
A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is possible to read arbitrary files from the local filesystem of the Kibana instance running Code with the permission of the Kibana system user.
Attacker Value
Unknown

CVE-2019-7616

Disclosure Date: July 30, 2019 (last updated November 27, 2024)
Kibana versions before 6.8.2 and 7.2.1 contain a server side request forgery (SSRF) flaw in the graphite integration for Timelion visualizer. An attacker with administrative Kibana access could set the timelion:graphite.url configuration option to an arbitrary URL. This could possibly lead to an attacker accessing external URL resources as the Kibana process on the host system.
Attacker Value
Unknown

CVE-2019-7610

Disclosure Date: March 25, 2019 (last updated November 27, 2024)
Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.security.audit.enabled set to true, an attacker could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
0
Attacker Value
Unknown

CVE-2019-7608

Disclosure Date: March 25, 2019 (last updated November 27, 2024)
Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XSS) vulnerability that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
0
Attacker Value
Unknown

CVE-2018-17245

Disclosure Date: December 20, 2018 (last updated November 27, 2024)
Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating PDF reports. If a report requests external resources plaintext credentials are included in the HTTP request that could be recovered by an external resource provider.
0
Attacker Value
Unknown

CVE-2018-17246

Disclosure Date: December 20, 2018 (last updated November 27, 2024)
Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
0