VYPR

Kibana

by Elastic

npm: kibana

Source repositories

CVEs (194)

  • CVE-2021-22139MedMay 13, 2021
    risk 0.42cvss 6.5epss 0.01

    Kibana versions before 7.12.1 contain a denial of service vulnerability was found in the webhook actions due to a lack of timeout or a limit on the request size. An attacker with permissions to create webhook actions could drain the Kibana host connection pool, making Kibana…

  • CVE-2019-7618MedOct 1, 2019
    risk 0.42cvss 6.5epss 0.01

    A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is possible to read arbitrary files from the local filesystem of the Kibana instance running Code with the permission of the Kibana…

  • CVE-2017-8443MedJun 30, 2017
    risk 0.42cvss 6.5epss 0.01

    In Kibana X-Pack security versions prior to 5.4.3 if a Kibana user opens a crafted Kibana URL the result could be a redirect to an improperly initialized Kibana login screen. If the user enters credentials on this screen, the credentials will appear in the URL bar. The…

  • CVE-2016-10364MedJun 16, 2017
    risk 0.42cvss 6.5epss 0.01

    With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any authenticated user could make requests to those services regardless of their own permissions.

  • CVE-2016-1000219HigJun 16, 2017
    risk 0.42cvss 7.5epss 0.02

    Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers could be written to the log files. This information could be used to hijack sessions of other users when using Kibana behind some form of authentication such as…

  • CVE-2026-63141MedJul 21, 2026
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without the required feature privileges, via direct requests to insufficiently protected product endpoints.

  • CVE-2026-78590HigSep 2, 2026
    risk 0.40cvss 7.3epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet Settings write access could cause…

  • CVE-2026-78592HigSep 1, 2026
    risk 0.40cvss 7.3epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Kibana can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding tag creation privileges could cause a subsequent…

  • CVE-2025-68387MedDec 18, 2025
    risk 0.40cvss 6.1epss 0.00

    Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an unauthenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via a vulnerability a function…

  • CVE-2024-23442MedJun 14, 2024
    risk 0.40cvss 6.1epss 0.00

    An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.

  • CVE-2022-38779MedFeb 22, 2023
    risk 0.40cvss 6.1epss 0.01

    An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.

  • CVE-2021-22141MedNov 18, 2022
    risk 0.40cvss 6.1epss 0.01

    An open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously crafted URL, it could result in Kibana redirecting the user to an arbitrary website.

  • CVE-2022-23713MedJul 6, 2022
    risk 0.40cvss 6.1epss 0.01

    A cross-site-scripting (XSS) vulnerability was discovered in the Vega Charts Kibana integration which could allow arbitrary JavaScript to be executed in a victim’s browser.

  • CVE-2022-23710MedMar 3, 2022
    risk 0.40cvss 6.1epss 0.01

    A cross-site-scripting (XSS) vulnerability was discovered in the Data Preview Pane (previously known as Index Pattern Preview Pane) which could allow arbitrary JavaScript to be executed in a victim’s browser.

  • CVE-2020-27816MedDec 2, 2020
    risk 0.40cvss 6.1epss 0.01

    The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it is possible to replace the original openshift-logging console link (kibana console) to different one, created based on the new CR for the new kibana resource.…

  • CVE-2018-3830MedSep 19, 2018
    risk 0.40cvss 6.1epss 0.02

    Kibana versions 5.3.0 to 6.4.1 had a cross-site scripting (XSS) vulnerability via the source field formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

  • CVE-2018-3821MedMar 30, 2018
    risk 0.40cvss 6.1epss 0.01

    Kibana versions after 5.1.1 and before 5.6.7 and 6.1.3 had a cross-site scripting (XSS) vulnerability in the tag cloud visualization that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

  • CVE-2018-3820MedMar 30, 2018
    risk 0.40cvss 6.1epss 0.01

    Kibana versions after 6.1.0 and before 6.1.3 had a cross-site scripting (XSS) vulnerability in labs visualizations that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

  • CVE-2018-3819MedMar 30, 2018
    risk 0.40cvss 6.1epss 0.01

    The fix in Kibana for ESA-2017-23 was incomplete. With X-Pack security enabled, Kibana versions before 6.1.3 and 5.6.7 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.

  • CVE-2018-3818MedMar 30, 2018
    risk 0.40cvss 6.1epss 0.01

    Kibana versions 5.1.1 to 6.1.2 and 5.6.6 had a cross-site scripting (XSS) vulnerability via the colored fields formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

Page 5 of 10