Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-22142

Опубликовано: 25 мая 2021
Источник: redhat
CVSS3: 6.6

Описание

Kibana contains an embedded version of the Chromium browser that the Reporting feature uses to generate the downloadable reports. If a user with permissions to generate reports is able to render arbitrary HTML with this browser, they may be able to leverage known Chromium vulnerabilities to conduct further attacks. Kibana contains a number of protections to prevent this browser from rendering arbitrary content.

Kibana contains an embedded version of the Chromium browser that the Reporting feature uses. An attacker potentially is able to leverage known Chromium vulnerabilities to conduct further attacks.

Отчет

The kibana reporting feature is part of the X-Pack features [1]. In OpenShift Container Platform (OCP) the kibana components have X-Pack security features disabled by default. The X-Pack plugin can be used only in the enterprise version [2] [3]. Hence the open source version is unaffected by this vulnerability. [1] https://www.elastic.co/guide/en/kibana/current/reporting-getting-started.html [2] https://www.elastic.co/guide/en/elasticsearch/reference/current/setup-xpack.html [3] https://www.elastic.co/subscriptions

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Not affected
Red Hat OpenShift Container Platform 3.11kibanaNot affected
Red Hat OpenShift Container Platform 4kibanaNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-logging-kibana6Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1021
https://bugzilla.redhat.com/show_bug.cgi?id=1965466kibana: Use of Unmaintained Third Party Components

6.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.6
nvd
около 2 лет назад

Kibana contains an embedded version of the Chromium browser that the Reporting feature uses to generate the downloadable reports. If a user with permissions to generate reports is able to render arbitrary HTML with this browser, they may be able to leverage known Chromium vulnerabilities to conduct further attacks. Kibana contains a number of protections to prevent this browser from rendering arbitrary content.

CVSS3: 6.6
debian
около 2 лет назад

Kibana contains an embedded version of the Chromium browser that the R ...

CVSS3: 6.6
github
около 2 лет назад

Kibana contains an embedded version of the Chromium browser that the Reporting feature uses to generate the downloadable reports. If a user with permissions to generate reports is able to render arbitrary HTML with this browser, they may be able to leverage known Chromium vulnerabilities to conduct further attacks. Kibana contains a number of protections to prevent this browser from rendering arbitrary content.

6.6 Medium

CVSS3