In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive information or perform destructive actions on behalf of Kibana users who view the region map visualization.
References
| Link | Resource |
|---|---|
| https://www.elastic.co/community/security/ | Vendor Advisory |
| https://discuss.elastic.co/t/elastic-stack-6-8-11-and-7-8-1-security-update/242786 | Release Notes Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-07-27 18:15
Updated : 2021-07-20 23:15
NVD link : CVE-2020-7017
Mitre link : CVE-2020-7017
JSON object : View
Products Affected
elasticsearch
- kibana
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
