A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a request that crashes the Kibana server process.
2023-02-08T21:15:10.583
2025-03-25T15:15:15.250
Modified
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | decode-uri-component_project | decode-uri-component | < 0.2.1 | Yes |
Application | elastic | kibana | < 7.17.9 | Yes |
Application | elastic | kibana | < 8.6.1 | Yes |