VYPR
Medium severity6.1NVD Advisory· Published Jun 5, 2017· Updated May 13, 2026

CVE-2017-8440

CVE-2017-8440

Description

Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

Affected products

5
  • Elastic/Kibanav55 versions
    5.3.0 to 5.3.3+ 4 more
    • (no CPE)range: 5.3.0 to 5.3.3
    • cpe:2.3:a:elastic:kibana:5.3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:elastic:kibana:5.3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:elastic:kibana:5.3.2:*:*:*:*:*:*:*
    • cpe:2.3:a:elastic:kibana:5.4.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.