CVE-2020-7017Cross-site Scripting in Elasticsearch Kibana

Severity
6.7MEDIUMNVD
EPSS
1.2%
top 21.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 27
Latest updateMay 24

Description

In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive information or perform destructive actions on behalf of Kibana users who view the region map visualization.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:LExploitability: 1.2 | Impact: 5.5

🔴Vulnerability Details

2
GHSA
GHSA-68q8-gcx9-m4rq: In Kibana versions before 62022-05-24
CVEList
CVE-2020-7017: In Kibana versions before 62020-07-27

📋Vendor Advisories

2
Oracle
Oracle Oracle Communications Applications Risk Matrix: Balance Monitoring Manager (Kibana) — CVE-2020-70172021-07-15
Red Hat
kibana: stored XSS in region map visualization2020-07-27

💬Community

1
Bugzilla
CVE-2020-7017 kibana: stored XSS in region map visualization2020-08-04
CVE-2020-7017 — Cross-site Scripting in Elasticsearch | cvebase