CVE-2022-23710: XSS
Published Mar 3, 2022
·Updated
A cross-site-scripting (XSS) vulnerability was discovered in the Data Preview Pane (previously known as Index Pattern Preview Pane) which could allow arbitrary JavaScript to be executed in a victim’s browser.
Affected Software
2 affected components
Elastic Kibana>=7.15.0<=7.17.0
Elastic Kibana=8.0.0
Event History
Mar 3, 2022
CVE Published
via MITRE·09:51 PM
Data Sourced
via MITRE·09:51 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-23710?
CVE-2022-23710 is a cross-site-scripting (XSS) vulnerability in the Data Preview Pane of Elastic Kibana.
2
How does CVE-2022-23710 impact users?
CVE-2022-23710 allows arbitrary JavaScript to be executed in a victim's browser when viewing the Data Preview Pane.
3
What software versions are affected by CVE-2022-23710?
CVE-2022-23710 affects Elastic Kibana versions 7.15.0 to 7.17.0, as well as version 8.0.0.
4
What is the severity of CVE-2022-23710?
CVE-2022-23710 has a severity rating of medium with a CVSS score of 6.1.
5
How can I fix CVE-2022-23710?
To fix CVE-2022-23710, upgrade to Elastic Kibana version 7.17.1 or later.