VYPR

Kibana

by Kibana

Source repositories

CVEs (25)

  • CVE-2016-1000220MedJun 16, 2017
    risk 0.33cvss 6.1epss 0.01

    Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScript in users' browsers.

  • CVE-2026-49092MedJul 21, 2026
    risk 0.28cvss 4.3epss 0.00

    Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a lower-privileged user can cause data from sources they are…

  • CVE-2019-7621MedDec 18, 2019
    risk 0.28cvss 5.4epss 0.01

    Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with the ability to create coordinate map visualizations could create a malicious visualization. If another Kibana user views that…

  • CVE-2019-7616MedJul 30, 2019
    risk 0.25cvss 4.9epss 0.02

    Kibana versions before 6.8.2 and 7.2.1 contain a server side request forgery (SSRF) flaw in the graphite integration for Timelion visualizer. An attacker with administrative Kibana access could set the timelion:graphite.url configuration option to an arbitrary URL. This could…

  • CVE-2021-22151LowNov 22, 2023
    risk 0.20cvss 3.1epss 0.01

    It was discovered that Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host to load internal files ending in the .pbf extension.

Page 2 of 2