Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-37939

Опубликовано: 18 нояб. 2021
Источник: nvd
CVSS3: 2.7
CVSS2: 4
EPSS Низкий

Описание

It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, which may be intentionally hidden from public view. Using this vulnerability, a malicious user with the ability to create connectors, could utilize these connectors to view limited HTTP response data on hosts accessible to the cluster.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
Версия от 7.8.0 (включая) до 7.15.2 (исключая)

EPSS

Процентиль: 29%
0.00108
Низкий

2.7 Low

CVSS3

4 Medium

CVSS2

Дефекты

CWE-200
CWE-319

Связанные уязвимости

CVSS3: 2.7
redhat
около 4 лет назад

It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, which may be intentionally hidden from public view. Using this vulnerability, a malicious user with the ability to create connectors, could utilize these connectors to view limited HTTP response data on hosts accessible to the cluster.

github
больше 3 лет назад

Kibana Sensitive Data Disclosure

EPSS

Процентиль: 29%
0.00108
Низкий

2.7 Low

CVSS3

4 Medium

CVSS2

Дефекты

CWE-200
CWE-319