Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xxj8-h2w8-grp8

Опубликовано: 13 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The identifier is stored as provided and is later incorporated into the request that Kibana issues when that configuration is removed.

Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The identifier is stored as provided and is later incorporated into the request that Kibana issues when that configuration is removed.

EPSS

Процентиль: 20%
0.00272
Низкий

7.3 High

CVSS3

Дефекты

CWE-23

Связанные уязвимости

CVSS3: 7.3
nvd
5 дней назад

Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The identifier is stored as provided and is later incorporated into the request that Kibana issues when that configuration is removed.

CVSS3: 7.3
debian
5 дней назад

Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorize ...

EPSS

Процентиль: 20%
0.00272
Низкий

7.3 High

CVSS3

Дефекты

CWE-23