CVE-2015-9056Cross-site Scripting in Kibana

Severity
6.1MEDIUMNVD
EPSS
0.3%
top 47.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 16
Latest updateMay 13

Description

Kibana versions prior to 4.1.3 and 4.2.1 are vulnerable to a XSS attack.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDelastic/kibana4.1.04.1.3+2
CVEListV5elastic/kibanabefore 4.1.3 and 4.2.1

🔴Vulnerability Details

2
GHSA
GHSA-cfv4-h42w-jx2h: Kibana versions prior to 42022-05-13
CVEList
CVE-2015-9056: Kibana versions prior to 42017-06-16

📋Vendor Advisories

1
Red Hat
kibana: Cross-site scripting in kibana prior to 4.1.3 and 4.2.12017-07-10

💬Community

1
Bugzilla
CVE-2015-9056 kibana: Cross-site scripting in kibana prior to 4.1.3 and 4.2.12017-07-26
CVE-2015-9056 — Cross-site Scripting in Elastic Kibana | cvebase