Описание
Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which could allow an attacker to read arbitrary files from the Kibana server filesystem, and perform Server-Side Request Forgery (SSRF) via Code Injection (CAPEC-242). This requires an authenticated user who has the workflowsManagement:executeWorkflow privilege.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
EPSS
8.6 High
CVSS3
7.7 High
CVSS3
Дефекты
Связанные уязвимости
Improper Neutralization of Special Elements Used in a Template Engine ...
Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which could allow an attacker to read arbitrary files from the Kibana server filesystem, and perform Server-Side Request Forgery (SSRF) via Code Injection (CAPEC-242). This requires an authenticated user who has the workflowsManagement:executeWorkflow privilege.
EPSS
8.6 High
CVSS3
7.7 High
CVSS3