Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qf29-h8cg-2hg4

Опубликовано: 28 мая 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to bypass the operator-configured connector allowlist, causing the Kibana server to issue outbound requests to destinations the egress controls were intended to block.

Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to bypass the operator-configured connector allowlist, causing the Kibana server to issue outbound requests to destinations the egress controls were intended to block.

EPSS

Процентиль: 10%
0.00199
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 6.3
nvd
2 месяца назад

Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to bypass the operator-configured connector allowlist, causing the Kibana server to issue outbound requests to destinations the egress controls were intended to block.

CVSS3: 6.3
debian
2 месяца назад

Server-Side Request Forgery (CWE-918) in Kibana can allow an authentic ...

EPSS

Процентиль: 10%
0.00199
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-918