In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive information or perform destructive actions on behalf of Kibana users who view the region map visualization.
2020-07-27T18:15:14.233
2024-11-21T05:36:30.080
Modified
CVSSv3.1: 6.7 (MEDIUM)
AV:N/AC:H/Au:S/C:P/I:P/A:P
3.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | elasticsearch | kibana | < 6.8.11 | Yes |
Application | elasticsearch | kibana | < 7.8.1 | Yes |
Application | oracle | communications_billing_and_revenue_management | 12.0.0.3.0 | Yes |
Application | oracle | communications_cloud_native_core_network_function_cloud_native_environment | 1.7.0 | Yes |
Application | oracle | peoplesoft_enterprise_peopletools | 8.58 | Yes |