CVE-2018-3821: XSS
Kibana versions after 5.1.1 and before 5.6.7 and 6.1.3 had a cross-site scripting (XSS) vulnerability in the tag cloud visualization that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-3821?
CVE-2018-3821 is a cross-site scripting (XSS) vulnerability in Kibana versions after 5.1.1 and before 5.6.7 and 6.1.3.
Which software versions are affected by CVE-2018-3821?
Kibana versions after 5.1.1 and before 5.6.7 and 6.1.3 are affected by CVE-2018-3821.
What is the severity level of CVE-2018-3821?
CVE-2018-3821 has a severity level of medium with a severity value of 6.1.
How can an attacker exploit CVE-2018-3821?
An attacker can exploit CVE-2018-3821 to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
How can I fix CVE-2018-3821?
To fix CVE-2018-3821, update your Kibana installation to version 5.6.7 or above if you are using Kibana 5.x, or to version 6.1.3 or above if you are using Kibana 6.x.