CVE-2020-10743: Medium severity Elastic Kibana vulnerability
It was discovered that kibana could be opened in an iframe, which made it possible to intercept and manipulate requests. An attacker could use this flaw to trick a user into performing arbitrary actions in kibana (clickjacking).
Other sources
It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercept and manipulate requests. This flaw allows an attacker to trick a user into performing arbitrary actions in OCP's distribution of Kibana, such as clickjacking.
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-10743?
CVE-2020-10743 is a vulnerability discovered in OpenShift Container Platform's (OCP) distribution of Kibana that allows an attacker to intercept and manipulate requests through a clickjacking attack.
How severe is CVE-2020-10743?
CVE-2020-10743 has a severity rating of low, with a severity value of 3.1.
How does CVE-2020-10743 affect OpenShift Container Platform?
CVE-2020-10743 affects OpenShift Container Platform's distribution of Kibana by allowing an attacker to trick a user into performing arbitrary actions in Kibana.
Is there a fix for CVE-2020-10743?
Yes, a fix for CVE-2020-10743 has been provided by the vendor. It is recommended to update to the latest version of OpenShift Container Platform's distribution of Kibana.
Where can I find more information about CVE-2020-10743?
More information about CVE-2020-10743 can be found in the references provided: [GitHub Issue](https://github.com/gardener/gardener/issues/1860), [GitHub Issue](https://github.com/elastic/kibana/issues/52809), and [GitHub Pull Request](https://github.com/elastic/kibana/pull/13045).