Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hp5f-qqrw-c8gj

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью

Описание

Kibana Sensitive Data Disclosure

It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, which may be intentionally hidden from public view. Using this vulnerability, a malicious user with the ability to create connectors, could utilize these connectors to view limited HTTP response data on hosts accessible to the cluster.

Пакеты

Наименование

kibana

npm
Затронутые версииВерсия исправления

>= 7.8.0, <= 7.15.1

7.15.2

EPSS

Процентиль: 29%
0.00108
Низкий

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 2.7
redhat
около 4 лет назад

It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, which may be intentionally hidden from public view. Using this vulnerability, a malicious user with the ability to create connectors, could utilize these connectors to view limited HTTP response data on hosts accessible to the cluster.

CVSS3: 2.7
nvd
около 4 лет назад

It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, which may be intentionally hidden from public view. Using this vulnerability, a malicious user with the ability to create connectors, could utilize these connectors to view limited HTTP response data on hosts accessible to the cluster.

EPSS

Процентиль: 29%
0.00108
Низкий

Дефекты

CWE-319