Elastic Kibana
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*
- >= 7.17.6, <= 7.17.23
- >= 8.4.0, <= 8.11.4
A vulnerability in Kibana allowing unrestricted upload of files with dangerous types can lead to arbitrary execution of JavaScript in a victim's browser, resulting in cross-site scripting (XSS). This issue arises from the ability to upload crafted HTML and JavaScript files. The vulnerability affects Kibana versions 7.17.6 prior to 7.17.24 and 8.4.0 prior to 8.11.4. To exploit this vulnerability, an attacker must have access to the Synthetics app or the ability to write to the synthetics indices.
Exploitation of this vulnerability allows for cross-site scripting, where an attacker can execute malicious JavaScript in the context of the victim's browser.
Users can upgrade to Kibana versions 7.17.24 or 8.12.0 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.