Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-23713

Опубликовано: 06 июл. 2022
Источник: redhat
CVSS3: 6.1

Описание

A cross-site-scripting (XSS) vulnerability was discovered in the Vega Charts Kibana integration which could allow arbitrary JavaScript to be executed in a victim’s browser.

A Cross-site-scripting (XSS) vulnerability was found in the Vega Charts Kibana integration. This issue could allow arbitrary JavaScript to be executed in a victim’s browser.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-rhel8-operatorAffected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-rhel8-operatorAffected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Not affected
Red Hat JBoss Fuse 6kibanaOut of support scope
Red Hat JBoss Fuse Service Works 6kibanaOut of support scope
Red Hat OpenShift Container Platform 3.11kibanaOut of support scope
Red Hat OpenShift Container Platform 3.11openshift3/ose-logging-kibana5Out of support scope
Red Hat OpenStack Platform 13 (Queens)puppet-kibana3Out of support scope
Red Hat OpenStack Platform 16.1puppet-kibana3Will not fix
Red Hat OpenStack Platform 16.2puppet-kibana3Will not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2172353kibana: Kibana cross-site-scripting (XSS) issue (ESA-2022-08)

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
больше 3 лет назад

A cross-site-scripting (XSS) vulnerability was discovered in the Vega Charts Kibana integration which could allow arbitrary JavaScript to be executed in a victim’s browser.

CVSS3: 6.1
github
больше 3 лет назад

A cross-site-scripting (XSS) vulnerability was discovered in the Vega Charts Kibana integration which could allow arbitrary JavaScript to be executed in a victim’s browser.

6.1 Medium

CVSS3