Описание
Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s browser (XSS) via crafted HTML and JavaScript files.
The attacker must have access to the Synthetics app AND/OR have access to write to the synthetics indices.
Ссылки
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 7.17.6 (включая) до 7.17.24 (исключая)Версия от 8.4.0 (включая) до 8.12.0 (исключая)
Одно из
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
EPSS
Процентиль: 25%
0.00087
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-434
Связанные уязвимости
CVSS3: 5.4
debian
9 месяцев назад
Unrestricted upload of a file with dangerous type in Kibana can lead t ...
CVSS3: 5.4
github
9 месяцев назад
Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s browser (XSS) via crafted HTML and JavaScript files. The attacker must have access to the Synthetics app AND/OR have access to write to the synthetics indices.
EPSS
Процентиль: 25%
0.00087
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-434