cbcvebase.
CVE-2022-38900
published 2023-02-08

CVE-2022-38900: A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a request that crashes…

medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a request that crashes the Kibana server process.

Affected

7 ranges
VendorProductVersion rangeFixed in
atlassianconfluence_data_center
decode-uri-component_projectdecode-uri-component< 0.2.10.2.1
decode-uri-component_projectdecode-uri-component
decode-uri-component_projectdecode-uri-component>= 0 < 0.2.10.2.1
elastickibana
elastickibana>= 7.0.0 < 7.17.97.17.9
elastickibana>= 8.0.0 < 8.6.18.6.1