CVE-2018-3830: XSS
Published Sep 19, 2018
·Updated
Kibana versions 5.3.0 to 6.4.1 had a cross-site scripting (XSS) vulnerability via the source field formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
Affected Software
4 affected componentsFixes available
redhat/kibana<5.6.12
5.6.12
redhat/kibana<6.4.1
6.4.1
Elastic Kibana>=5.3.0<=6.4.1
redhat OpenShift Container Platform=3.11
Event History
Sep 19, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-3830?
CVE-2018-3830 is a cross-site scripting (XSS) vulnerability in Kibana versions 5.3.0 to 6.4.1.
2
How does CVE-2018-3830 affect Kibana?
CVE-2018-3830 allows an attacker to perform cross-site scripting attacks in Kibana, potentially obtaining sensitive information or performing malicious actions on behalf of other users.
3
What is the severity of CVE-2018-3830?
CVE-2018-3830 has a severity rating of 6.1, which is considered medium.
4
Which versions of Kibana are affected by CVE-2018-3830?
Kibana versions 5.3.0 to 6.4.1 are affected by CVE-2018-3830.
5
How can CVE-2018-3830 be remediated?
To remediate CVE-2018-3830, it is recommended to update to Kibana version 5.6.12 or higher.