Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-43ww-gwmw-f89v

Опубликовано: 28 мая 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.7

Описание

Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured connection allowlist. By configuring a Webhook connector with a crafted target, an attacker can cause Kibana to issue outbound requests to destinations that the egress restriction controls were intended to block.

Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured connection allowlist. By configuring a Webhook connector with a crafted target, an attacker can cause Kibana to issue outbound requests to destinations that the egress restriction controls were intended to block.

EPSS

Процентиль: 22%
0.003
Низкий

7.7 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 7.7
nvd
3 месяца назад

Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured connection allowlist. By configuring a Webhook connector with a crafted target, an attacker can cause Kibana to issue outbound requests to destinations that the egress restriction controls were intended to block.

CVSS3: 7.7
debian
3 месяца назад

Server-Side Request Forgery (CWE-918) in Kibana allows authenticated u ...

EPSS

Процентиль: 22%
0.003
Низкий

7.7 High

CVSS3

Дефекты

CWE-918