Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9674-77c9-4xpr

Опубликовано: 26 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which could allow an attacker to read arbitrary files from the Kibana server filesystem, and perform Server-Side Request Forgery (SSRF) via Code Injection (CAPEC-242). This requires an authenticated user who has the workflowsManagement:executeWorkflow privilege.

Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which could allow an attacker to read arbitrary files from the Kibana server filesystem, and perform Server-Side Request Forgery (SSRF) via Code Injection (CAPEC-242). This requires an authenticated user who has the workflowsManagement:executeWorkflow privilege.

EPSS

Процентиль: 16%
0.0005
Низкий

8.6 High

CVSS3

Дефекты

CWE-1336

Связанные уязвимости

CVSS3: 8.6
nvd
около 1 месяца назад

Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which could allow an attacker to read arbitrary files from the Kibana server filesystem, and perform Server-Side Request Forgery (SSRF) via Code Injection (CAPEC-242). This requires an authenticated user who has the workflowsManagement:executeWorkflow privilege.

CVSS3: 8.6
debian
около 1 месяца назад

Improper Neutralization of Special Elements Used in a Template Engine ...

EPSS

Процентиль: 16%
0.0005
Низкий

8.6 High

CVSS3

Дефекты

CWE-1336