Show filters
74 Total Results
Displaying 51-60 of 74
Sort by:
Attacker Value
Unknown
CVE-2018-3830
Disclosure Date: September 19, 2018 (last updated November 27, 2024)
Kibana versions 5.3.0 to 6.4.1 had a cross-site scripting (XSS) vulnerability via the source field formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
0
Attacker Value
Unknown
CVE-2018-3824
Disclosure Date: September 19, 2018 (last updated November 27, 2024)
X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. If an attacker is able to inject data into an index that has a ML job running against it, then when another user views the results of the ML job it could allow the attacker to obtain sensitive information from or perform destructive actions on behalf of that other ML user.
0
Attacker Value
Unknown
CVE-2018-3823
Disclosure Date: September 19, 2018 (last updated November 27, 2024)
X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. Users with manage_ml permissions could create jobs containing malicious data as part of their configuration that could allow the attacker to obtain sensitive information from or perform destructive actions on behalf of other ML users viewing the results of the jobs.
0
Attacker Value
Unknown
CVE-2018-3818
Disclosure Date: March 30, 2018 (last updated November 26, 2024)
Kibana versions 5.1.1 to 6.1.2 and 5.6.6 had a cross-site scripting (XSS) vulnerability via the colored fields formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
0
Attacker Value
Unknown
CVE-2018-3820
Disclosure Date: March 30, 2018 (last updated November 26, 2024)
Kibana versions after 6.1.0 and before 6.1.3 had a cross-site scripting (XSS) vulnerability in labs visualizations that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
0
Attacker Value
Unknown
CVE-2018-3821
Disclosure Date: March 30, 2018 (last updated November 26, 2024)
Kibana versions after 5.1.1 and before 5.6.7 and 6.1.3 had a cross-site scripting (XSS) vulnerability in the tag cloud visualization that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
0
Attacker Value
Unknown
CVE-2018-3819
Disclosure Date: March 30, 2018 (last updated November 26, 2024)
The fix in Kibana for ESA-2017-23 was incomplete. With X-Pack security enabled, Kibana versions before 6.1.3 and 5.6.7 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.
0
Attacker Value
Unknown
CVE-2017-11482
Disclosure Date: December 08, 2017 (last updated November 26, 2024)
The Kibana fix for CVE-2017-8451 was found to be incomplete. With X-Pack installed, Kibana versions before 6.0.1 and 5.6.5 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.
0
Attacker Value
Unknown
CVE-2017-11481
Disclosure Date: December 08, 2017 (last updated November 26, 2024)
Kibana versions prior to 6.0.1 and 5.6.5 had a cross-site scripting (XSS) vulnerability via URL fields that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
0
Attacker Value
Unknown
CVE-2017-11479
Disclosure Date: September 29, 2017 (last updated November 26, 2024)
Kibana versions prior to 5.6.1 had a cross-site scripting (XSS) vulnerability in Timelion that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
0