Описание
It was discovered that Kibana was not sanitizing document fields containing HTML snippets. Using this vulnerability, an attacker with the ability to write documents to an elasticsearch index could inject HTML. When the Discover app highlighted a search term containing the HTML, it would be rendered for the user.
A flaw was found in Kibana. This issue occurs due to Kibana not sanitizing document fields containing HTML snippets. An attacker with the ability to write documents to an elasticsearch index could inject HTML. When the Discover app highlighted a search term containing the HTML, it would be rendered for the user.
Отчет
- Red Hat OpenShift Logging uses Kibana 5.x which is not affected by this CVE.
- The puppet-kibana3 package is shipped in Red Hat OpenStack which is not affected by this CVE.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Logging Subsystem for Red Hat OpenShift | openshift-logging/elasticsearch-rhel8-operator | Not affected | ||
| Logging Subsystem for Red Hat OpenShift | openshift-logging/kibana6-rhel8 | Not affected | ||
| Red Hat JBoss Fuse 6 | kibana | Out of support scope | ||
| Red Hat JBoss Fuse Service Works 6 | kibana | Out of support scope | ||
| Red Hat OpenShift Container Platform 3.11 | kibana | Out of support scope | ||
| Red Hat OpenShift Container Platform 3.11 | openshift3/ose-logging-kibana5 | Out of support scope | ||
| Red Hat OpenStack Platform 13 (Queens) | puppet-kibana3 | Not affected | ||
| Red Hat OpenStack Platform 16.1 | puppet-kibana3 | Not affected | ||
| Red Hat OpenStack Platform 16.2 | puppet-kibana3 | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.4 Medium
CVSS3
Связанные уязвимости
It was discovered that Kibana was not sanitizing document fields containing HTML snippets. Using this vulnerability, an attacker with the ability to write documents to an elasticsearch index could inject HTML. When the Discover app highlighted a search term containing the HTML, it would be rendered for the user.
It was discovered that Kibana was not sanitizing document fields conta ...
It was discovered that Kibana was not sanitizing document fields containing HTML snippets. Using this vulnerability, an attacker with the ability to write documents to an elasticsearch index could inject HTML. When the Discover app highlighted a search term containing the HTML, it would be rendered for the user.
EPSS
5.4 Medium
CVSS3