← Back

CVE-2022-23707

nvd nist
Published: Feb 11, 2022Modified: Nov 21, 2024

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

An XSS vulnerability was found in Kibana index patterns. Using this vulnerability, an authenticated user with permissions to create index patterns can inject malicious javascript into the index pattern which could execute against other users

Affected (1)

Products: Elastic: Kibana
1 product
Kibana
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 7.5.1 to 7.17.0

References (2)

Source: security@elastic.co
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.