CVE-2020-7015: XSS
Published Jun 3, 2020
·Updated
Kibana versions before 6.8.9 and 7.7.0 contains a stored XSS flaw in the TSVB visualization. An attacker who is able to edit or create a TSVB visualization could allow the attacker to obtain sensitive information from, or perform destructive actions, on behalf of Kibana users who edit the TSVB visualization.
Affected Software
4 affected componentsFixes available
redhat/kibana<7.7.1
7.7.1
redhat/kibana<6.8.10
6.8.10
Elastic Kibana<6.8.10
Elastic Kibana>=7.0.0<7.7.1
Remediation
Information
To mitigate this vulnerability you can set "metrics.enabled: false" in kibana.yml
Event History
Jun 3, 2020
CVE Published
12:00 AM
Data Sourced
12:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·05:55 PM
Data Sourced
via MITRE·05:55 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-7015.
2
What is the title of the vulnerability?
The title of the vulnerability is 'Kibana versions before 6.8.9 and 7.7.0 stored XSS flaw in TSVB visualization.'
3
What is the severity of CVE-2020-7015?
The severity of CVE-2020-7015 is medium.
4
What is the affected software?
Kibana versions before 6.8.9 and 7.7.0 are affected.
5
How can I fix CVE-2020-7015?
Upgrade Kibana to version 6.8.10 or 7.7.1 to fix CVE-2020-7015.