First published: Mon Jul 27 2020(Updated: )
In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive information or perform destructive actions on behalf of Kibana users who view the region map visualization.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elasticsearch Kibana | <6.8.11 | |
Elasticsearch Kibana | >=7.0.0<7.8.1 | |
Oracle Communications Billing and Revenue Management | =12.0.0.3.0 | |
Oracle Communications Cloud Native Core Network Function Cloud Native Environment | =1.7.0 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.58 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-7017.
The title of this vulnerability is 'In Kibana versions before 6.8.11 and 7.8.1 the region map visualization contains a stored XSS flaw.'
The severity of CVE-2020-7017 is medium with a severity value of 6.7.
Kibana versions before 6.8.11 and 7.8.1, Oracle Communications Billing and Revenue Management 12.0.0.3.0, Oracle Communications Cloud Native Core Network Function Cloud Native Environment 1.7.0, and Oracle PeopleSoft Enterprise PeopleTools 8.58 are affected by CVE-2020-7017.
An attacker who is able to edit or create a region map visualization could obtain sensitive information or perform destructive actions on behalf of Kibana users who view the region map visualization.