#VU53541 Security features bypass in Kibana - CVE-2021-22142
Published: May 25, 2021
Kibana
Elastic Stack
Description
The vulnerability allows a remote user to compromise the affected system.
The vulnerability exists due to Kibana contains an embedded version of the Chromium browser that the
Reporting feature uses to generate the downloadable reports. A remote user
with permissions to generate reports can render arbitrary HTML
with this Chromium browser and try to leverage known Chromium
vulnerabilities to conduct further attacks.