CVE-2016-10366Cross-site Scripting in Kibana

Severity
6.1MEDIUMNVD
EPSS
0.3%
top 49.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 16
Latest updateMay 13

Description

Kibana versions after and including 4.3 and before 4.6.2 are vulnerable to a cross-site scripting (XSS) attack.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

CVEListV5elastic/kibana4.3 to 4.6.2
NVDelastic/kibana14 versions+13

🔴Vulnerability Details

2
GHSA
GHSA-2fr8-xhpc-wf7p: Kibana versions after and including 42022-05-13
CVEList
CVE-2016-10366: Kibana versions after and including 42017-06-16

📋Vendor Advisories

1
Red Hat
kibana: Cross-site scripting (XSS) in kibana up to 4.3 and before 4.6.22017-07-10

💬Community

1
Bugzilla
CVE-2016-10366 kibana: Cross-site scripting (XSS) in kibana up to 4.3 and before 4.6.22017-07-26
CVE-2016-10366 — Cross-site Scripting in Elastic Kibana | cvebase