CVE-2024-11390: Kibana Unrestricted Upload of File with Dangerous Type Can Lead to XSS
Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s browser (XSS) via crafted HTML and JavaScript files.
The attacker must have access to the Synthetics app AND/OR have access to write to the synthetics indices.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11390?
CVE-2024-11390 is considered a high severity vulnerability due to the potential for arbitrary JavaScript execution in victim's browsers.
How do I fix CVE-2024-11390?
To mitigate CVE-2024-11390, upgrade to the latest version of Kibana where the vulnerability has been patched.
What types of files are involved in CVE-2024-11390?
CVE-2024-11390 involves unrestricted uploads of files with dangerous types, specifically crafted HTML and JavaScript files.
Who can exploit CVE-2024-11390?
An attacker must have access to the Synthetics app and/or permission to write to the synthetics indices to exploit CVE-2024-11390.
What are the potential impacts of CVE-2024-11390?
The potential impact of CVE-2024-11390 includes the execution of arbitrary JavaScript which can lead to cross-site scripting (XSS) in a victim’s browser.