First published: Wed Jun 03 2020(Updated: )
Kibana versions before 6.8.9 and 7.7.0 contains a stored XSS flaw in the TSVB visualization. An attacker who is able to edit or create a TSVB visualization could allow the attacker to obtain sensitive information from, or perform destructive actions, on behalf of Kibana users who edit the TSVB visualization.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kibana | <7.7.1 | 7.7.1 |
redhat/kibana | <6.8.10 | 6.8.10 |
Elastic Kibana | <6.8.10 | |
Elastic Kibana | >=7.0.0<7.7.1 |
To mitigate this vulnerability you can set "metrics.enabled: false" in kibana.yml
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-7015.
The title of the vulnerability is 'Kibana versions before 6.8.9 and 7.7.0 stored XSS flaw in TSVB visualization.'
The severity of CVE-2020-7015 is medium.
Kibana versions before 6.8.9 and 7.7.0 are affected.
Upgrade Kibana to version 6.8.10 or 7.7.1 to fix CVE-2020-7015.