Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-22136

Опубликовано: 23 мар. 2021
Источник: redhat
CVSS3: 4

Описание

In Kibana versions before 7.12.0 and 6.8.15 a flaw in the session timeout was discovered where the xpack.security.session.idleTimeout setting is not being respected. This was caused by background polling activities unintentionally extending authenticated users sessions, preventing a user session from timing out.

Отчет

In OpenShift Container Platform (OCP) the kibana components have X-Pack security features disabled by default. The X-Pack plugin can be used only is an enterprise version [1]. Hence the open source version is unaffected by this vulnerability. [1] https://www.elastic.co/subscriptions

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Not affected
Red Hat OpenShift Container Platform 3.11kibanaNot affected
Red Hat OpenShift Container Platform 4kibanaNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-logging-kibana6Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-613
https://bugzilla.redhat.com/show_bug.cgi?id=1943200kibana: xpack.security.session.idleTimeout setting timeout not being respected

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.5
nvd
больше 4 лет назад

In Kibana versions before 7.12.0 and 6.8.15 a flaw in the session timeout was discovered where the xpack.security.session.idleTimeout setting is not being respected. This was caused by background polling activities unintentionally extending authenticated users sessions, preventing a user session from timing out.

CVSS3: 3.5
debian
больше 4 лет назад

In Kibana versions before 7.12.0 and 6.8.15 a flaw in the session time ...

github
больше 3 лет назад

In Kibana versions before 7.12.0 and 6.8.15 a flaw in the session timeout was discovered where the xpack.security.session.idleTimeout setting is not being respected. This was caused by background polling activities unintentionally extending authenticated users sessions, preventing a user session from timing out.

4 Medium

CVSS3