CVE-2022-23713: XSS
A cross-site-scripting (XSS) vulnerability was discovered in the Vega Charts Kibana integration which could allow arbitrary JavaScript to be executed in a victim’s browser.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-23713?
CVE-2022-23713 is a cross-site-scripting (XSS) vulnerability in the Vega Charts Kibana integration.
What software is affected by CVE-2022-23713?
The Elastic Kibana software versions 7.0.0 to 7.17.5 and versions 8.0.0 to 8.2.3 are affected by CVE-2022-23713.
How severe is CVE-2022-23713?
CVE-2022-23713 has a severity score of 6.1, categorized as medium.
How can CVE-2022-23713 be exploited?
CVE-2022-23713 can be exploited by injecting arbitrary JavaScript code into a victim's browser through the Vega Charts Kibana integration.
How can I protect myself from CVE-2022-23713?
To protect yourself from CVE-2022-23713, update your Elastic Kibana software to versions 7.17.6 or 8.2.4 or apply the recommended security updates provided by Elastic.