CVE-2015-9056: XSS
Published Jun 16, 2017
·Updated
Kibana versions prior to 4.1.3 and 4.2.1 are vulnerable to a XSS attack.
Affected Software
4 affected components
Elastic Kibana>=4.1.0<4.1.3
Elastic Kibana>=4.2.0<4.2.1
Elastic Kibana=4.2.0-beta1
Elastic Kibana=4.2.0-beta2
Event History
Jun 16, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2015-9056?
CVE-2015-9056 is classified as a high severity vulnerability due to its potential exploitation via XSS attacks.
2
How do I fix CVE-2015-9056?
To fix CVE-2015-9056, upgrade Kibana to versions 4.1.3 or 4.2.1 or later.
3
Which versions of Kibana are affected by CVE-2015-9056?
Kibana versions prior to 4.1.3 and 4.2.1, including 4.2.0-beta1 and 4.2.0-beta2, are affected by CVE-2015-9056.
4
What type of attack is CVE-2015-9056 associated with?
CVE-2015-9056 is associated with Cross-Site Scripting (XSS) attacks.
5
Can CVE-2015-9056 be exploited remotely?
Yes, CVE-2015-9056 can be exploited remotely, making it a significant security risk.