First published: Wed Dec 18 2019(Updated: )
Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with the ability to create coordinate map visualizations could create a malicious visualization. If another Kibana user views that visualization or a dashboard containing the visualization it could execute JavaScript in the victim�s browser.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic Kibana | <6.8.6 | |
Elastic Kibana | >=7.0.0<7.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7621 is a vulnerability in Kibana versions before 6.8.6 and 7.5.1 that allows for cross-site scripting (XSS) attacks.
CVE-2019-7621 affects Kibana versions before 6.8.6 and 7.5.1 by enabling attackers to execute malicious code through cross-site scripting (XSS) attacks.
CVE-2019-7621 has a severity rating of 5.4, which is considered medium.
To fix CVE-2019-7621, it is recommended to upgrade Kibana to version 6.8.6 or 7.5.1 or later, as these versions contain the necessary security updates.
More information about CVE-2019-7621 can be found in the references provided: [Link 1](https://discuss.elastic.co/t/elastic-stack-6-8-6-and-7-5-1-security-update/212390) and [Link 2](https://www.elastic.co/community/security/).