Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-37939

Опубликовано: 10 нояб. 2021
Источник: redhat
CVSS3: 2.7

Описание

It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, which may be intentionally hidden from public view. Using this vulnerability, a malicious user with the ability to create connectors, could utilize these connectors to view limited HTTP response data on hosts accessible to the cluster.

An information disclosure flaw was found in kibana. A malicious user with the ability to create connectors could utilize the JIRA and IBM Resilient connectors to view limited HTTP response data on hosts accessible to the cluster.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Not affected
Red Hat OpenShift Container Platform 3.11kibanaNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-logging-kibana6Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-319
https://bugzilla.redhat.com/show_bug.cgi?id=2027187kibana: HTTP server information disclosure via JIRA and IBM Resilient connectors

2.7 Low

CVSS3

Связанные уязвимости

CVSS3: 2.7
nvd
около 4 лет назад

It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, which may be intentionally hidden from public view. Using this vulnerability, a malicious user with the ability to create connectors, could utilize these connectors to view limited HTTP response data on hosts accessible to the cluster.

github
больше 3 лет назад

Kibana Sensitive Data Disclosure

2.7 Low

CVSS3