Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2026-33458

4 месяца назад

Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and execution privileges can bypass host allowlist restrictions in the Workflows Execution Engine, potentially exposing sensitive internal endpoints and data.

CVSS3: 6.3
EPSS: Низкий
debian логотип

CVE-2026-33458

4 месяца назад

Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead ...

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-grxp-xwh4-267v

4 месяца назад

Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and execution privileges can bypass host allowlist restrictions in the Workflows Execution Engine, potentially exposing sensitive internal endpoints and data.

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-33458

Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and execution privileges can bypass host allowlist restrictions in the Workflows Execution Engine, potentially exposing sensitive internal endpoints and data.

CVSS3: 6.3
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-33458

Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead ...

CVSS3: 6.3
0%
Низкий
4 месяца назад
github логотип
GHSA-grxp-xwh4-267v

Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and execution privileges can bypass host allowlist restrictions in the Workflows Execution Engine, potentially exposing sensitive internal endpoints and data.

CVSS3: 6.3
0%
Низкий
4 месяца назад

Уязвимостей на страницу