Elastic Kibana
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*
- >= 8.19.0, < 8.19.14
- >= 9.2.0, < 9.2.8
- >= 9.3.0, < 9.3.3
A vulnerability in Elastic Kibana exists due to incorrect authorization, allowing cross-space information disclosure through privilege abuse. Users with Fleet agent management rights in one Kibana space can access Fleet Server policy details from other spaces via an internal enrollment endpoint. This endpoint bypasses space-scoped access controls by utilizing an unscoped internal client, and it exposes operational identifiers, policy names, management states, and infrastructure linkage details from unauthorized spaces.
Exploitation of this vulnerability could result in unauthorized access to sensitive information across different spaces in Kibana, specifically related to Fleet Server policies and their management details.
Users can update to Kibana versions 8.19.14, 9.2.8, or 9.3.3 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.