CVE-2021-37938: Path Traversal
It was discovered that on Windows operating systems specifically, Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host to load internal files ending in the .pbf extension. Thanks to Dominic Couture for finding this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-37938?
CVE-2021-37938 is a vulnerability found in Kibana on Windows operating systems that allows a malicious user to load internal files with arbitrary paths ending in the .pbf extension.
How does CVE-2021-37938 affect Elastic Kibana?
CVE-2021-37938 affects Elastic Kibana versions 7.9.0 to 7.15.2 on Windows operating systems.
What is the severity of CVE-2021-37938?
The severity of CVE-2021-37938 is medium with a CVSS score of 4.3.
How can a malicious user exploit CVE-2021-37938?
A malicious user can exploit CVE-2021-37938 by supplying a user path to load arbitrary internal files with the .pbf extension.
Is there a security update available for CVE-2021-37938?
Yes, Elastic Kibana 7.15.2 includes a security update for CVE-2021-37938.