Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w6m5-9xjg-jf9w

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with the ability to create coordinate map visualizations could create a malicious visualization. If another Kibana user views that visualization or a dashboard containing the visualization it could execute JavaScript in the victim?s browser.

Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with the ability to create coordinate map visualizations could create a malicious visualization. If another Kibana user views that visualization or a dashboard containing the visualization it could execute JavaScript in the victim?s browser.

EPSS

Процентиль: 57%
0.00349
Низкий

Связанные уязвимости

CVSS3: 5.4
redhat
около 6 лет назад

Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with the ability to create coordinate map visualizations could create a malicious visualization. If another Kibana user views that visualization or a dashboard containing the visualization it could execute JavaScript in the victim�s browser.

CVSS3: 5.4
nvd
около 6 лет назад

Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with the ability to create coordinate map visualizations could create a malicious visualization. If another Kibana user views that visualization or a dashboard containing the visualization it could execute JavaScript in the victim�s browser.

CVSS3: 5.4
debian
около 6 лет назад

Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting ...

EPSS

Процентиль: 57%
0.00349
Низкий