← Back

CVE-2021-37936

nvd nist
Published: Nov 18, 2022Modified: Apr 29, 2025

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

It was discovered that Kibana was not sanitizing document fields containing HTML snippets. Using this vulnerability, an attacker with the ability to write documents to an elasticsearch index could inject HTML. When the Discover app highlighted a search term containing the HTML, it would be rendered for the user.

Affected (1)

Products: Elastic: Kibana
1 product
Kibana
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 7.14.1

References (4)

Source: security@elastic.co
MitigationVendor Advisory
Source: security@elastic.co
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory

Timeline

No history available yet.