Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p8x3-m7c8-mcj5

Опубликовано: 19 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

It was discovered that Kibana was not sanitizing document fields containing HTML snippets. Using this vulnerability, an attacker with the ability to write documents to an elasticsearch index could inject HTML. When the Discover app highlighted a search term containing the HTML, it would be rendered for the user.

It was discovered that Kibana was not sanitizing document fields containing HTML snippets. Using this vulnerability, an attacker with the ability to write documents to an elasticsearch index could inject HTML. When the Discover app highlighted a search term containing the HTML, it would be rendered for the user.

EPSS

Процентиль: 68%
0.00555
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
redhat
около 3 лет назад

It was discovered that Kibana was not sanitizing document fields containing HTML snippets. Using this vulnerability, an attacker with the ability to write documents to an elasticsearch index could inject HTML. When the Discover app highlighted a search term containing the HTML, it would be rendered for the user.

CVSS3: 5.4
nvd
около 3 лет назад

It was discovered that Kibana was not sanitizing document fields containing HTML snippets. Using this vulnerability, an attacker with the ability to write documents to an elasticsearch index could inject HTML. When the Discover app highlighted a search term containing the HTML, it would be rendered for the user.

CVSS3: 5.4
debian
около 3 лет назад

It was discovered that Kibana was not sanitizing document fields conta ...

EPSS

Процентиль: 68%
0.00555
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79