Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-31422

Опубликовано: 26 окт. 2023
Источник: nvd
CVSS3: 9
CVSS3: 7.5
EPSS Низкий

Описание

An issue was discovered by Elastic whereby sensitive information is recorded in Kibana logs in the event of an error. The issue impacts only Kibana version 8.10.0 when logging in the JSON layout or when the pattern layout is configured to log the %meta pattern. Elastic has released Kibana 8.10.1 which resolves this issue. The error object recorded in the log contains request information, which can include sensitive data, such as authentication credentials, cookies, authorization headers, query params, request paths, and other metadata. Some examples of sensitive data which can be included in the logs are account credentials for kibana_system, kibana-metricbeat, or Kibana end-users.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:elastic:kibana:8.10.0:*:*:*:*:*:*:*

EPSS

Процентиль: 49%
0.00257
Низкий

9 Critical

CVSS3

7.5 High

CVSS3

Дефекты

CWE-532
CWE-532

Связанные уязвимости

CVSS3: 7.5
redhat
больше 2 лет назад

An issue was discovered by Elastic whereby sensitive information is recorded in Kibana logs in the event of an error. The issue impacts only Kibana version 8.10.0 when logging in the JSON layout or when the pattern layout is configured to log the %meta pattern. Elastic has released Kibana 8.10.1 which resolves this issue. The error object recorded in the log contains request information, which can include sensitive data, such as authentication credentials, cookies, authorization headers, query params, request paths, and other metadata. Some examples of sensitive data which can be included in the logs are account credentials for kibana_system, kibana-metricbeat, or Kibana end-users.

CVSS3: 9
debian
больше 2 лет назад

An issue was discovered by Elastic whereby sensitive information is re ...

CVSS3: 9
github
больше 2 лет назад

An issue was discovered by Elastic whereby sensitive information is recorded in Kibana logs in the event of an error. The issue impacts only Kibana version 8.10.0 when logging in the JSON layout or when the pattern layout is configured to log the %meta pattern. Elastic has released Kibana 8.10.1 which resolves this issue. The error object recorded in the log contains request information, which can include sensitive data, such as authentication credentials, cookies, authorization headers, query params, request paths, and other metadata. Some examples of sensitive data which can be included in the logs are account credentials for kibana_system, kibana-metricbeat, or Kibana end-users.

CVSS3: 9
fstec
больше 2 лет назад

Уязвимость сервиса визуализации данных Kibana, связанная с недостаточной защитой регистрационных данных, позволяющая нарушителю получить несанкционированный доступ к учетным данным

EPSS

Процентиль: 49%
0.00257
Низкий

9 Critical

CVSS3

7.5 High

CVSS3

Дефекты

CWE-532
CWE-532