First published: Wed Nov 22 2023(Updated: )
Kibana contains an embedded version of the Chromium browser that the Reporting feature uses to generate the downloadable reports. If a user with permissions to generate reports is able to render arbitrary HTML with this browser, they may be able to leverage known Chromium vulnerabilities to conduct further attacks. Kibana contains a number of protections to prevent this browser from rendering arbitrary content.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic Kibana | >=7.0.0<7.13.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this Kibana Reporting vulnerability is CVE-2021-22142.
The severity of CVE-2021-22142 is high.
The affected software for CVE-2021-22142 is Elastic Kibana versions 7.0.0 to 7.13.0.
The Common Weakness Enumeration (CWE) ID for CVE-2021-22142 is 1104.
To fix the Kibana Reporting vulnerability (CVE-2021-22142), it is recommended to upgrade to a version of Elastic Kibana that is not affected by the vulnerability.