Medium severity6.1NVD Advisory· Published Mar 3, 2022· Updated Jun 17, 2026
CVE-2022-23710
CVE-2022-23710
Description
A cross-site-scripting (XSS) vulnerability was discovered in the Data Preview Pane (previously known as Index Pattern Preview Pane) which could allow arbitrary JavaScript to be executed in a victim’s browser.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.elasticsearch:elasticsearchMaven | >= 7.16.0, < 7.17.1 | 7.17.1 |
Affected products
4For self-managed deployments the issue impacts versions 7.15.0, 7.15.1, and 7.15.2 For Elastic Cloud Services the issue impacts versions 7.15.0 through 7.17.0, and 8.0.0+ 2 more
- (no CPE)range: For self-managed deployments the issue impacts versions 7.15.0, 7.15.1, and 7.15.2 For Elastic Cloud Services the issue impacts versions 7.15.0 through 7.17.0, and 8.0.0
- cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*range: >=7.15.0,<=7.17.0
- cpe:2.3:a:elastic:kibana:8.0.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
5- discuss.elastic.co/t/elastic-stack-7-17-1-security-update/298447nvdRelease NotesVendor AdvisoryWEB
- github.com/advisories/GHSA-m6gg-86c6-gfr9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-23710ghsaADVISORY
- security.netapp.com/advisory/ntap-20220325-0009/nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20220325-0009ghsaWEB
News mentions
0No linked articles in our index yet.