Filters

Elastic KibanaA deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse…

First published (updated )

Elastic KibanaKibana arbitrary code execution via prototype pollution

First published (updated )

Elastic KibanaA high-privileged user, allowed to create custom osquery packs 17 could affect the availability of K…

First published (updated )

Elastic KibanaKibana open redirect issue

First published (updated )

Elastic KibanaKibana Broken Access Control issue

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Elastic KibanaKibana Broken Access Control issue

EPSS
0.05%
First published (updated )

Elastic KibanaKibana Insertion of Sensitive Information into Log File

First published (updated )

Elastic KibanaKibana Insertion of Sensitive Information into Log File

First published (updated )

Elastic KibanaKibana Reporting vulnerabilities

8.8
First published (updated )

Elastic KibanaKibana path traversal issue

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Elastic KibanaKibana code execution issue

7.2
First published (updated )

Elastic KibanaKibana Insertion of Sensitive Information into Log File

First published (updated )

Elastic KibanaCode Injection

8.8
First published (updated )

Elastic KibanaCode Injection

8.8
First published (updated )

Elastic KibanaAn open redirect issue was discovered in Kibana that could lead to a user being redirected to an arb…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Elastic KibanaInput Validation

First published (updated )

Elastic KibanaXSS

First published (updated )

Elastic KibanaAn open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user vis…

First published (updated )

Elastic KibanaXSS

First published (updated )

Elastic KibanaInfoleak

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Elastic KibanaXSS

First published (updated )

Elastic KibanaA flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify a…

First published (updated )

Elastic KibanaXSS

First published (updated )

Elastic KibanaInfoleak

First published (updated )

Elastic KibanaPath Traversal

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Elastic KibanaKibana versions before 7.12.1 contain a denial of service vulnerability was found in the webhook act…

First published (updated )

Elastic KibanaIn Kibana versions before 7.12.0 and 6.8.15 a flaw in the session timeout was discovered where the x…

3.6
First published (updated )

redhat/elasticsearch-operator-containerThe elasticsearch-operator does not validate the namespace where kibana logging resource is created …

First published (updated )

Elastic KibanaCode Injection

8.8
First published (updated )

redhat/kibanaXSS

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

redhat/kibanaCode Injection

7.2
First published (updated )

Redhat Openshift Container PlatformIt was discovered that kibana could be opened in an iframe, which made it possible to intercept and …

First published (updated )

Elastic KibanaXSS

First published (updated )

Elastic KibanaPath Traversal

First published (updated )

Elastic KibanaSSRF

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

redhat/kibanaCommand Injection, Code Injection

First published (updated )

redhat/kibanaXSS

First published (updated )

Elastic KibanaKibana Arbitrary Code Execution

First published (updated )

Elastic KibanaKibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorizatio…

First published (updated )

Elastic KibanaKibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plug…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Elastic KibanaXSS

First published (updated )

Elastic KibanaXSS

First published (updated )

Elastic KibanaThe fix in Kibana for ESA-2017-23 was incomplete. With X-Pack security enabled, Kibana versions befo…

First published (updated )

Elastic KibanaXSS

First published (updated )

Elastic KibanaXSS

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Elastic KibanaThe Kibana fix for CVE-2017-8451 was found to be incomplete. With X-Pack installed, Kibana versions …

First published (updated )

Elastic KibanaXSS

First published (updated )

Elastic KibanaXSS

First published (updated )

Elastic KibanaInfoleak

First published (updated )

Elastic KibanaWith X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to …

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203