Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an unauthenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via a vulnerability a function handler in the Vega AST evaluator.
2025-12-18T23:15:49.300
2025-12-23T19:07:16.837
Analyzed
CVSSv3.1: 6.1 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | elastic | kibana | ≤ 7.17.29 | Yes |
| Application | elastic | kibana | < 8.19.9 | Yes |
| Application | elastic | kibana | < 9.1.9 | Yes |
| Application | elastic | kibana | < 9.2.3 | Yes |