Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-22142

Опубликовано: 22 нояб. 2023
Источник: nvd
CVSS3: 6.6
CVSS3: 8.8
EPSS Низкий

Описание

Kibana contains an embedded version of the Chromium browser that the Reporting feature uses to generate the downloadable reports. If a user with permissions to generate reports is able to render arbitrary HTML with this browser, they may be able to leverage known Chromium vulnerabilities to conduct further attacks. Kibana contains a number of protections to prevent this browser from rendering arbitrary content.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
Версия от 7.0.0 (включая) до 7.13.0 (исключая)

EPSS

Процентиль: 64%
0.0047
Низкий

6.6 Medium

CVSS3

8.8 High

CVSS3

Дефекты

CWE-1104
NVD-CWE-Other

Связанные уязвимости

CVSS3: 6.6
redhat
больше 4 лет назад

Kibana contains an embedded version of the Chromium browser that the Reporting feature uses to generate the downloadable reports. If a user with permissions to generate reports is able to render arbitrary HTML with this browser, they may be able to leverage known Chromium vulnerabilities to conduct further attacks. Kibana contains a number of protections to prevent this browser from rendering arbitrary content.

CVSS3: 6.6
debian
около 2 лет назад

Kibana contains an embedded version of the Chromium browser that the R ...

CVSS3: 6.6
github
около 2 лет назад

Kibana contains an embedded version of the Chromium browser that the Reporting feature uses to generate the downloadable reports. If a user with permissions to generate reports is able to render arbitrary HTML with this browser, they may be able to leverage known Chromium vulnerabilities to conduct further attacks. Kibana contains a number of protections to prevent this browser from rendering arbitrary content.

EPSS

Процентиль: 64%
0.0047
Низкий

6.6 Medium

CVSS3

8.8 High

CVSS3

Дефекты

CWE-1104
NVD-CWE-Other