Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-23707

Опубликовано: 03 фев. 2022
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

An XSS vulnerability was found in Kibana index patterns. Using this vulnerability, an authenticated user with permissions to create index patterns can inject malicious javascript into the index pattern which could execute against other users

A Cross-Site Scripting (XSS) vulnerability was found in Kibana index patterns. Using this vulnerability, an authenticated user with permission to create index patterns can inject malicious javascript into the index pattern, which could execute against other users.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-rhel8-operatorWill not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Will not fix
Red Hat JBoss Fuse 6KibanaOut of support scope
Red Hat JBoss Fuse Service Works 6KibanaOut of support scope
Red Hat OpenShift Container Platform 3.11kibanaWill not fix
Red Hat OpenShift Container Platform 3.11openshift3/ose-logging-kibana5Will not fix
Red Hat OpenShift Container Platform 4openshift4/ose-elasticsearch-operatorWill not fix
Red Hat OpenShift Container Platform 4openshift4/ose-logging-kibana6Will not fix
Red Hat OpenStack Platform 13 (Queens)puppet-kibana3Out of support scope
Red Hat OpenStack Platform 16.1puppet-kibana3Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2051419Kibana: Cross-site scripting issue (ESA-2022-01)

EPSS

Процентиль: 62%
0.00436
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
почти 4 года назад

An XSS vulnerability was found in Kibana index patterns. Using this vulnerability, an authenticated user with permissions to create index patterns can inject malicious javascript into the index pattern which could execute against other users

CVSS3: 5.4
debian
почти 4 года назад

An XSS vulnerability was found in Kibana index patterns. Using this vu ...

github
почти 4 года назад

An XSS vulnerability was found in Kibana index patterns. Using this vulnerability, an authenticated user with permissions to create index patterns can inject malicious javascript into the index pattern which could execute against other users

EPSS

Процентиль: 62%
0.00436
Низкий

8.1 High

CVSS3