CVE-2019-7608: XSS
Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XSS) vulnerability that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-7608?
CVE-2019-7608 is a cross-site scripting (XSS) vulnerability in Kibana versions before 5.6.15 and 6.6.1.
How does CVE-2019-7608 affect Kibana?
CVE-2019-7608 allows an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
What is the severity of CVE-2019-7608?
The severity of CVE-2019-7608 is medium, with a CVSS score of 6.1.
How can I fix CVE-2019-7608?
To fix CVE-2019-7608, update Kibana to version 5.6.15 if you are using versions before 5.6.15, or update to version 6.6.1 if you are using versions between 6.0.0 and 6.6.1.
Where can I find more information about CVE-2019-7608?
You can find more information about CVE-2019-7608 at the following references: [link1](https://discuss.elastic.co/t/elastic-stack-6-6-1-and-5-6-15-security-update/169077), [link2](https://access.redhat.com/errata/RHSA-2019:2860), [link3](https://access.redhat.com/security/cve/cve-2019-7608).