← Back

CVE-2018-3821

nvd nist
Published: Mar 30, 2018Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Kibana versions after 5.1.1 and before 5.6.7 and 6.1.3 had a cross-site scripting (XSS) vulnerability in the tag cloud visualization that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

Affected (2)

Products: Elastic: Kibana
1 product
Kibana
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Elastic
After 5.1.1 to 5.6.7
From 6.0.0 to 6.1.3

References (2)

Timeline

No history available yet.