CVE-2021-22136: Low severity elastic vulnerability
In Kibana versions before 7.12.0 and 6.8.15 a flaw in the session timeout was discovered where the xpack.security.session.idleTimeout setting is not being respected. This was caused by background polling activities unintentionally extending authenticated users sessions, preventing a user session from timing out.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-22136?
CVE-2021-22136 is a vulnerability in Kibana versions before 7.12.0 and 6.8.15 that allows background polling activities to extend authenticated users' sessions, bypassing the session timeout.
How does CVE-2021-22136 impact Kibana?
CVE-2021-22136 affects Kibana versions before 7.12.0 and 6.8.15 by not respecting the session timeout, allowing user sessions to be extended unintentionally.
What is the severity of CVE-2021-22136?
CVE-2021-22136 has a severity rating of 3.5 (low).
How can I fix CVE-2021-22136?
To fix CVE-2021-22136, upgrade your Kibana installation to version 7.12.0 or 6.8.15.
Where can I find more information about CVE-2021-22136?
You can find more information about CVE-2021-22136 at the following link: [Click here](https://discuss.elastic.co/t/elastic-stack-7-12-0-and-6-8-15-security-update/268125).