First published: Wed Sep 19 2018(Updated: )
Kibana versions 5.3.0 to 6.4.1 had a cross-site scripting (XSS) vulnerability via the source field formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic Kibana | >=5.3.0<=6.4.1 | |
Redhat Openshift Container Platform | =3.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-3830 is a cross-site scripting (XSS) vulnerability in Kibana versions 5.3.0 to 6.4.1.
CVE-2018-3830 allows an attacker to perform cross-site scripting attacks in Kibana, potentially obtaining sensitive information or performing malicious actions on behalf of other users.
CVE-2018-3830 has a severity rating of 6.1, which is considered medium.
Kibana versions 5.3.0 to 6.4.1 are affected by CVE-2018-3830.
To remediate CVE-2018-3830, it is recommended to update to Kibana version 5.6.12 or higher.