CVE-2022-38778: Input Validation
Published Feb 8, 2023
·Updated
A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a request that crashes the Kibana server process.
Affected Software
3 affected components
Decode-uri-component Project Decode-uri-component Node.js<0.2.1
Elastic Kibana>=7.0.0<7.17.9
Elastic Kibana>=8.0.0<8.6.1
Event History
Feb 8, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this flaw?
The vulnerability ID for this flaw is CVE-2022-38778.
2
What is the severity level of CVE-2022-38778?
The severity level of CVE-2022-38778 is medium with a score of 6.5.
3
Which software is affected by CVE-2022-38778?
The software affected by CVE-2022-38778 includes Kibana versions between 7.0.0 and 7.17.9, as well as versions between 8.0.0 and 8.6.1.
4
What can an authenticated user do with CVE-2022-38778?
An authenticated user can perform a request that crashes the Kibana server process using CVE-2022-38778.
5
How can I fix CVE-2022-38778?
To fix CVE-2022-38778, it is recommended to update to a patched version of Kibana. Please refer to the Elastic Security Update page for more information.