Описание
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 9.4.0 (включая) до 9.4.4 (исключая)
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
EPSS
Процентиль: 8%
0.00181
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-639
Связанные уязвимости
CVSS3: 4.3
debian
15 дней назад
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana c ...
CVSS3: 4.3
github
15 дней назад
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access.
EPSS
Процентиль: 8%
0.00181
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-639