Elastic Kibana
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*
- >= 8.12.0, <= 8.19.6
- >= 9.1.0, <= 9.1.6
- 9.2.0
A vulnerability in Kibana related to origin validation can result in server-side request forgery (SSRF). This issue arises when a forged Origin HTTP header is processed by the Observability AI Assistant, allowing potentially malicious requests to be sent to internal services.
Exploitation of this vulnerability could lead to server-side request forgery, allowing an attacker to make requests to internal services on behalf of the server.
Users are advised to upgrade to Kibana versions 8.19.7, 9.1.7, or 9.2.1. For those using Elastic Cloud Serverless, this vulnerability has already been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.