Inclusion of sensitive information in log files in Kibana - CVE-2023-46671
Published: November 15, 2023
Kibana
Detailed vulnerability description
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to software stores sensitive information into log files when an error occurs. A local user can read the log files and gain access to sensitive data, such as account credentials for the kibana_system 1 user, API Keys, and credentials of Kibana end-users.