Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-23710

Опубликовано: 28 фев. 2022
Источник: redhat
CVSS3: 6.1

Описание

A cross-site-scripting (XSS) vulnerability was discovered in the Data Preview Pane (previously known as Index Pattern Preview Pane) which could allow arbitrary JavaScript to be executed in a victim’s browser.

A flaw was found in Kibana’s data preview pane. This issue allows a Cross-Site scripting attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-rhel8-operatorWill not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Will not fix
Red Hat JBoss Fuse 6KibanaOut of support scope
Red Hat JBoss Fuse Service Works 6KibanaOut of support scope
Red Hat OpenShift Container Platform 3.11kibanaWill not fix
Red Hat OpenShift Container Platform 3.11openshift3/ose-logging-kibana5Will not fix
Red Hat OpenShift Container Platform 4openshift4/ose-elasticsearch-operatorFix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-logging-kibana6Fix deferred
Red Hat OpenStack Platform 13 (Queens)puppet-kibana3Out of support scope
Red Hat OpenStack Platform 16.1puppet-kibana3Will not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2066387kibana: cross-site-scripting (XSS) issue (ESA-2022-04)

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
почти 4 года назад

A cross-site-scripting (XSS) vulnerability was discovered in the Data Preview Pane (previously known as Index Pattern Preview Pane) which could allow arbitrary JavaScript to be executed in a victim’s browser.

CVSS3: 6.1
debian
почти 4 года назад

A cross-site-scripting (XSS) vulnerability was discovered in the Data ...

CVSS3: 6.1
github
почти 4 года назад

Withdrawn: Cross-site Scripting in Kibana

6.1 Medium

CVSS3