It was discovered that Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host to load internal files ending in the .pbf extension.
2023-11-22T01:15:07.607
2024-11-21T05:49:36.413
Modified
CVSSv3.1: 3.1 (LOW)