Elastic Kibana
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*
- >= 9.0.0, <= 9.2.7
- >= 9.3.0, <= 9.3.1
A Server-Side Request Forgery (SSRF) vulnerability has been identified in Elastic Kibana. This issue allows authenticated users with connector management privileges to bypass the connection allowlist configured by operators. By setting up a Webhook connector with a manipulated target, an attacker can trick Kibana into sending outbound requests to blocked destinations, circumventing egress restrictions.
Exploitation of this vulnerability could lead to unauthorized network access, allowing attackers to interact with internal services or systems that are normally protected by egress controls.
Users can upgrade to Kibana versions 9.2.8 or 9.3.2 to address this vulnerability. For those using Elastic Cloud Serverless, the vulnerability has already been remediated.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.