Описание
Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload.
A cross site scripting vulnerability has been discovered in the Kibana logging platform. For an attacker to exploit this vulnerability they must have permission to upload files to the platform.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Logging Subsystem for Red Hat OpenShift | openshift-logging/kibana6-rhel8 | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
8.7 High
CVSS3
Связанные уязвимости
Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload.
Improper Neutralization of Input During Web Page Generation in Kibana ...
Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload.
Уязвимость сервиса визуализации данных Kibana, связанная с непринятием мер по защите структуры веб-страницы, позволяющая проводить межсайтовые сценарные атаки (XSS)
EPSS
8.7 High
CVSS3