First published: Wed Jul 06 2022(Updated: )
A cross-site-scripting (XSS) vulnerability was discovered in the Vega Charts Kibana integration which could allow arbitrary JavaScript to be executed in a victim’s browser.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic Kibana | >=7.0.0<7.17.5 | |
Elastic Kibana | >=8.0.0<=8.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23713 is a cross-site-scripting (XSS) vulnerability in the Vega Charts Kibana integration.
The Elastic Kibana software versions 7.0.0 to 7.17.5 and versions 8.0.0 to 8.2.3 are affected by CVE-2022-23713.
CVE-2022-23713 has a severity score of 6.1, categorized as medium.
CVE-2022-23713 can be exploited by injecting arbitrary JavaScript code into a victim's browser through the Vega Charts Kibana integration.
To protect yourself from CVE-2022-23713, update your Elastic Kibana software to versions 7.17.6 or 8.2.4 or apply the recommended security updates provided by Elastic.