← Back

CVE-2017-11479

nvd nist
Published: Sep 29, 2017Modified: May 13, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Kibana versions prior to 5.6.1 had a cross-site scripting (XSS) vulnerability in Timelion that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

Affected (22)

1 product
Kibana
1 product
Kibana
Configuration A
22 vulnerable
Vulnerable SoftwareAffected Versions
Elastic
Version 5.0.0
Version 5.0.1
Version 5.0.2
Version 5.1.1
Version 5.1.2
Version 5.2.0
Version 5.2.1
Version 5.2.2
Version 5.3.0
Version 5.3.1
Version 5.3.2
Version 5.3.3
Version 5.4.0
Version 5.4.1
Version 5.4.2
Version 5.4.3
Version 5.5.0
Version 5.5.1
Version 5.5.2
Version 5.5.3
Version 5.6.0
Version 5.1.0

References (6)

Source: security@elastic.co
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory

Timeline

No history available yet.