Описание
Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and execution privileges can bypass host allowlist restrictions in the Workflows Execution Engine, potentially exposing sensitive internal endpoints and data.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 9.3.0 (включая) до 9.3.3 (исключая)
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
EPSS
Процентиль: 14%
0.00226
Низкий
6.3 Medium
CVSS3
7.7 High
CVSS3
Дефекты
CWE-918
Связанные уязвимости
CVSS3: 6.3
debian
4 месяца назад
Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead ...
CVSS3: 6.3
github
4 месяца назад
Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and execution privileges can bypass host allowlist restrictions in the Workflows Execution Engine, potentially exposing sensitive internal endpoints and data.
EPSS
Процентиль: 14%
0.00226
Низкий
6.3 Medium
CVSS3
7.7 High
CVSS3
Дефекты
CWE-918