Описание
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.
Уязвимые конфигурации
Конфигурация 1Версия от 8.6.0 (включая) до 8.19.13 (исключая)Версия от 9.0.0 (включая) до 9.2.7 (исключая)Версия от 9.3.0 (включая) до 9.3.2 (исключая)
Одно из
cpe:2.3:a:elastic:endpoint_security:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:endpoint_security:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:endpoint_security:*:*:*:*:*:*:*:*
EPSS
Процентиль: 23%
0.00305
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-863
Связанные уязвимости
CVSS3: 5.3
github
2 месяца назад
Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.
EPSS
Процентиль: 23%
0.00305
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-863