VYPR

Kibana

by Elastic

npm: kibana

Source repositories

CVEs (194)

  • CVE-2024-43710MedJan 23, 2025
    risk 0.28cvss 4.3epss 0.00

    A server side request forgery vulnerability was identified in Kibana where the /api/fleet/health_check API could be used to send requests to internal endpoints. Due to the nature of the underlying request, only endpoints available over https that return JSON could be accessed.…

  • CVE-2024-37279MedJun 13, 2024
    risk 0.28cvss 4.3epss 0.00

    A flaw was discovered in Kibana, allowing view-only users of alerting to use the run_soon API making the alerting rule run continuously, potentially affecting the system availability if the alerting rule is running complex queries.

  • CVE-2022-23709MedMar 3, 2022
    risk 0.28cvss 4.3epss 0.01

    A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A user with this privilege would be able to create new alerting rules or overwrite existing ones. However, any new or modified rules would not be enabled, and a…

  • CVE-2021-37938MedNov 18, 2021
    risk 0.28cvss 4.3epss 0.01

    It was discovered that on Windows operating systems specifically, Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host to load internal files ending in the .pbf extension. Thanks…

  • CVE-2020-10743MedJun 2, 2021
    risk 0.28cvss 4.3epss 0.01

    It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercept and manipulate requests. This flaw allows an attacker to trick a user into performing arbitrary actions in OCP's distribution of…

  • CVE-2019-7621MedDec 18, 2019
    risk 0.28cvss 5.4epss 0.01

    Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with the ability to create coordinate map visualizations could create a malicious visualization. If another Kibana user views that…

  • CVE-2026-78581MedAug 25, 2026
    risk 0.27cvss 4.2epss 0.00

    Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized data modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, an authenticated user could reference another user's AI Assistant…

  • CVE-2026-33463MedMay 28, 2026
    risk 0.27cvss 5.3epss 0.00

    Operation on a Resource after Expiration or Termination (CWE-672) in Kibana can lead to unauthorized information disclosure. A logic error in how expiration timestamps were validated allowed a time-bounded access token to remain usable beyond its intended validity window,…

  • CVE-2019-7616MedJul 30, 2019
    risk 0.25cvss 4.9epss 0.02

    Kibana versions before 6.8.2 and 7.2.1 contain a server side request forgery (SSRF) flaw in the graphite integration for Timelion visualizer. An attacker with administrative Kibana access could set the timelion:graphite.url configuration option to an arbitrary URL. This could…

  • CVE-2026-33462MedMay 28, 2026
    risk 0.23cvss 4.6epss 0.00

    A path traversal vulnerability was identified in Kibana's dashboard management functionality. An authenticated user with limited permissions could create a dashboard with a specially crafted identifier. When an administrator subsequently attempts to delete this dashboard through…

  • CVE-2021-22136LowMay 13, 2021
    risk 0.23cvss 3.5epss 0.00

    In Kibana versions before 7.12.0 and 6.8.15 a flaw in the session timeout was discovered where the xpack.security.session.idleTimeout setting is not being respected. This was caused by background polling activities unintentionally extending authenticated users sessions,…

  • CVE-2026-78584MedSep 2, 2026
    risk 0.21cvss 4.3epss 0.00

    Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery live-query privileges could determine whether a scheduled query identifier exists in a…

  • CVE-2026-78603MedSep 1, 2026
    risk 0.21cvss 4.3epss 0.00

    Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding minimal Elasticsearch privileges could bypass Kibana feature authorization and space…

  • CVE-2026-78597MedSep 1, 2026
    risk 0.21cvss 4.3epss 0.00

    Missing Authorization (CWE-862) in the Kibana Entity Store feature can lead to unauthorized credential creation via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only low-privilege Security feature access could invoke an…

  • CVE-2026-72633MedSep 1, 2026
    risk 0.21cvss 4.3epss 0.00

    Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only read-level Security feature access, and no Elasticsearch privileges,…

  • CVE-2026-72655MedAug 13, 2026
    risk 0.21cvss 4.3epss 0.00

    Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case management functionality of Elastic Security in Kibana can lead to unauthorized modification of case data by an authenticated user who has not been granted case editing…

  • CVE-2026-33460MedApr 8, 2026
    risk 0.21cvss 4.3epss 0.00

    Incorrect Authorization (CWE-863) in Kibana can lead to cross-space information disclosure via Privilege Abuse (CAPEC-122). A user with Fleet agent management privileges in one Kibana space can retrieve Fleet Server policy details from other spaces through an internal enrollment…

  • CVE-2026-78606MedSep 1, 2026
    risk 0.20cvss 4.2epss 0.00

    Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Where two authenticated principals originating from different authentication realms share…

  • CVE-2026-42401MedMay 28, 2026
    risk 0.20cvss 4.1epss 0.00

    Improper Neutralization of Input During Web Page Generation (CWE-79) in Kibana can lead to stored HTML injection. A user with write access to an Elasticsearch index could persist crafted markup which, when subsequently rendered through an affected Kibana view by another user,…

  • CVE-2021-22151LowNov 22, 2023
    risk 0.20cvss 3.1epss 0.01

    It was discovered that Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host to load internal files ending in the .pbf extension.

Page 9 of 10