Описание
Improper Neutralization of Special Elements in Data Query Logic (CWE-943) in Kibana can lead to information disclosure via NoSQL Injection (CAPEC-676). An authenticated user with access to the affected query functionality could submit specially crafted input that alters the intended query logic, returning data the user is not authorized to read.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 9.4.0 (включая) до 9.4.5 (исключая)
Одно из
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:kibana:9.5.0:*:*:*:*:*:*:*
EPSS
Процентиль: 27%
0.00339
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-943
Связанные уязвимости
CVSS3: 6.5
github
23 дня назад
Improper Neutralization of Special Elements in Data Query Logic (CWE-943) in Kibana can lead to information disclosure via NoSQL Injection (CAPEC-676). An authenticated user with access to the affected query functionality could submit specially crafted input that alters the intended query logic, returning data the user is not authorized to read.
EPSS
Процентиль: 27%
0.00339
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-943