CVE-2020-7017
published 2020-07-27CVE-2020-7017: In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map…
PriorityP430medium6.7CVSS 3.1
AVNACHPRLUIRSUCHIHAL
EPSS
1.22%
65.5th percentile
In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive information or perform destructive actions on behalf of Kibana users who view the region map visualization.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| elastic | kibana | — | — |
| elasticsearch | kibana | < 6.8.11 | 6.8.11 |
| elasticsearch | kibana | >= 7.0.0 < 7.8.1 | 7.8.1 |
| oracle | communications_billing_and_revenue_management | — | — |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L
nvdv2.04.6MEDIUMAV:N/AC:H/Au:S/C:P/I:P/A:P
vendor_oracle6.7MEDIUM
vendor_redhat6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Applications Risk Matrix: Balance Monitoring Manager (Kibana) — CVE-2020-7017
vendor_oracle·2021-07-15·CVSS 6.7
CVE-2020-7017 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Balance Monitoring Manager (Kibana) — CVE-2020-7017
Oracle Oracle Communications Applications Risk Matrix: Balance Monitoring Manager (Kibana) vulnerability
CVE: CVE-2020-7017
CVSS: 6.7
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Red Hat
kibana: stored XSS in region map visualization
vendor_redhat·2020-07-27·CVSS 6.7
CVE-2020-7017 [MEDIUM] CWE-79 kibana: stored XSS in region map visualization
kibana: stored XSS in region map visualization
In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive information or perform destructive actions on behalf of Kibana users who view the region map visualization.
A stored Cross-site scripting (XSS) flaw was found in the region map visualization in kibana. This flaw allows an attacker who can edit or create a region map visualization to obtain sensitive information or perform destructive actions on behalf of kibana users who view the region map visualization. The highest threat from this vulnerability is to confidentiality, integrity, and system availability.
Statement: In Red Hat OpenShift Container Pl
GHSA
GHSA-68q8-gcx9-m4rq: In Kibana versions before 6
ghsa_unreviewed·2022-05-24
CVE-2020-7017 [LOW] CWE-79 GHSA-68q8-gcx9-m4rq: In Kibana versions before 6
In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive information or perform destructive actions on behalf of Kibana users who view the region map visualization.
No detection rules found.
No public exploits indexed.
https://discuss.elastic.co/t/elastic-stack-6-8-11-and-7-8-1-security-update/242786https://www.elastic.co/community/security/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://discuss.elastic.co/t/elastic-stack-6-8-11-and-7-8-1-security-update/242786https://www.elastic.co/community/security/https://www.oracle.com//security-alerts/cpujul2021.html
2020-07-27
Published