Описание
Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS)
A Cross-Site Scripting (XSS) vulnerability in Kibana’s Vega visualization engine. It results from improper input validation in Vega visualization specifications, allowing attackers to inject malicious JavaScript. Successful exploitation could lead to session hijacking, data theft, or privilege escalation within Kibana dashboards.
Отчет
This vulnerability is rated Important rather than Moderate because it allows unauthenticated remote exploitation through user interaction, enabling attackers to execute arbitrary JavaScript within the Kibana interface and compromise the confidentiality and integrity of dashboard data. Unlike moderate XSS issues confined to low-impact contexts, this flaw occurs in the Vega visualization engine, which operates within privileged browser sessions connected to sensitive Elastic data. The cross-context nature (S:C) and high integrity impact (I:H) in the CVSS vector indicate that an attacker can potentially elevate privileges, steal session tokens, or alter visualization outputs, posing a significant risk to operational security and data trust within the Kibana environment.
Меры по смягчению последствий
Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Logging Subsystem for Red Hat OpenShift | openshift-logging/cluster-logging-rhel9-operator | Not affected | ||
| Logging Subsystem for Red Hat OpenShift | openshift-logging/elasticsearch-rhel8-operator | Not affected | ||
| Logging Subsystem for Red Hat OpenShift | openshift-logging/elasticsearch-rhel9-operator | Not affected | ||
| Logging Subsystem for Red Hat OpenShift | openshift-logging/kibana6-rhel8 | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 8 | kibana | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 8 | org.elasticsearch.plugin/kibana | Not affected | ||
| Red Hat OpenShift distributed tracing 3 | rhosdt/tempo-jaeger-query-rhel8 | Affected | ||
| Red Hat OpenStack Platform 16.2 | puppet-kibana3 | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
8.2 High
CVSS3
Связанные уязвимости
Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation in Kibana ...
Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS)
EPSS
8.2 High
CVSS3