Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mq6c-w86q-vpp3

Опубликовано: 22 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5

Описание

Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.

Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.

EPSS

Процентиль: 7%
0.00172
Низкий

5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 5
nvd
15 дней назад

Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.

CVSS3: 5
debian
15 дней назад

Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an ...

EPSS

Процентиль: 7%
0.00172
Низкий

5 Medium

CVSS3

Дефекты

CWE-863