First published: Thu Mar 03 2022(Updated: )
A cross-site-scripting (XSS) vulnerability was discovered in the Data Preview Pane (previously known as Index Pattern Preview Pane) which could allow arbitrary JavaScript to be executed in a victim’s browser.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic Kibana | >=7.15.0<=7.17.0 | |
Elastic Kibana | =8.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23710 is a cross-site-scripting (XSS) vulnerability in the Data Preview Pane of Elastic Kibana.
CVE-2022-23710 allows arbitrary JavaScript to be executed in a victim's browser when viewing the Data Preview Pane.
CVE-2022-23710 affects Elastic Kibana versions 7.15.0 to 7.17.0, as well as version 8.0.0.
CVE-2022-23710 has a severity rating of medium with a CVSS score of 6.1.
To fix CVE-2022-23710, upgrade to Elastic Kibana version 7.17.1 or later.