SB2018033016 - Cross-site scripting in Kibana



SB2018033016 - Cross-site scripting in Kibana

Published: March 30, 2018 Updated: July 17, 2020

Security Bulletin ID SB2018033016
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Cross-site scripting (CVE-ID: CVE-2018-3820)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Kibana versions after 6.1.0 and before 6.1.3 had a cross-site scripting (XSS) vulnerability in labs visualizations that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.


Remediation

Install update from vendor's website.