Elastic Kibana
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*
- >= 8.16.1, <= 8.17.1
A prototype pollution vulnerability has been identified in Kibana, specifically in versions 8.16.1 through 8.17.1. This vulnerability can lead to code injection by exploiting unrestricted file uploads combined with path traversal.
Exploitation of this vulnerability allows for prototype pollution, which can lead to code injection.
Users should upgrade to Kibana versions 8.16.4, 8.17.2 or higher. For those unable to upgrade to these versions, the integration assistant can be disabled by setting 'xpack.integration_assistant.enabled' to 'false' in the 'kibana.yml' configuration file.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.