VYPR

Bitnami package

kibana

pkg:bitnami/kibana

Vulnerabilities (109)

  • CVE-2024-43707HigJan 23, 2025
    affected >= 8.0.0, < 8.15.0fixed 8.15.0

    An issue was identified in Kibana where a user without access to Fleet can view Elastic Agent policies that could contain sensitive information. The nature of the sensitive information depends on the integrations enabled for the Elastic Agent and their respective versions.

  • CVE-2024-37285CriNov 14, 2024
    affected >= 8.10.0, < 8.15.1fixed 8.15.1

    A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. A successful attack requires a malicious user to have a combination of both specific Elasticsearch indices privileges https://www.el

  • CVE-2024-37288CriSep 9, 2024
    affected >= 8.15.0, < 8.15.1fixed 8.15.1

    A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. This issue only affects users that use Elastic Security’s built-in AI tools https://www.elastic.co/guide/en/security/current/ai-for-

  • CVE-2024-37281MedJul 30, 2024
    affected >= 7.0.0, < 7.17.23fixed 7.17.23

    An issue was discovered in Kibana where a user with Viewer role could cause a Kibana instance to crash by sending a large number of maliciously crafted requests to a specific endpoint.

  • CVE-2024-23443MedJun 19, 2024
    affected < 8.14.0fixed 8.14.0

    A high-privileged user, allowed to create custom osquery packs 17 could affect the availability of Kibana by uploading a maliciously crafted osquery pack.

  • CVE-2024-23442MedJun 14, 2024
    affected < 7.17.22fixed 7.17.22

    An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.

  • CVE-2024-37279MedJun 13, 2024
    affected >= 8.6.3, < 8.14.0fixed 8.14.0

    A flaw was discovered in Kibana, allowing view-only users of alerting to use the run_soon API making the alerting rule run continuously, potentially affecting the system availability if the alerting rule is running complex queries.

  • CVE-2020-7017MedJul 27, 2020
    affected < 6.8.11fixed 6.8.11

    In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive information or perform destructive actions on behalf of Kibana users who view the reg

  • CVE-2020-7016MedJul 27, 2020
    affected < 6.8.11fixed 6.8.11

    Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consuming large amounts of CPU and becoming unresponsive.

Page 6 of 6