In Kibana versions before 7.12.0 and 6.8.15 a flaw in the session timeout was discovered where the xpack.security.session.idleTimeout setting is not being respected. This was caused by background polling activities unintentionally extending authenticated users sessions, preventing a user session from timing out.
2021-05-13T18:15:08.993
2024-11-21T05:49:34.560
Modified
CVSSv3.1: 3.5 (LOW)
AV:L/AC:L/Au:N/C:P/I:P/A:N
3.9
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | elastic | kibana | < 6.8.15 | Yes |
Application | elastic | kibana | < 7.12.0 | Yes |