CVE-2017-8440Cross-site Scripting in Kibana

Severity
6.1MEDIUMNVD
EPSS
0.3%
top 43.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 5
Latest updateMay 13

Description

Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

CVEListV5elastic/kibana5.3.0 to 5.3.3, 5.4.1+1
NVDelastic/kibana4 versions+3

🔴Vulnerability Details

2
GHSA
GHSA-jv8f-xj77-j348: Starting in version 52022-05-13
CVEList
CVE-2017-8440: Starting in version 52017-06-05

📋Vendor Advisories

1
Red Hat
kibana: XSS in Discover page could allow attacker to obtain sensitive information or perform user actions2017-06-05

💬Community

1
Bugzilla
CVE-2017-8440 kibana: XSS in Discover page could allow attacker to obtain sensitive information or perform user actions2018-01-11
CVE-2017-8440 — Cross-site Scripting in Elastic Kibana | cvebase