Back

MEDIUM

kibana: stored XSS in region map visualization

Published Jul 27, 2020

Description

In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive information or perform destructive actions on behalf of Kibana users who view the region map visualization.

Affected products

Remediation

Red Hat statement

In Red Hat OpenShift Container Platform (RHOCP) the affected kibana region map visualization is behind OpenShift OAuth authentication. This restricts access to the vulnerable visualization to authenticated users only, therefore the impact is Low. Red Hat OpenShift Container Platform 4 delivers the kibana package where the region map visualization is included, but due to the code changing to the container first content, the kibana package is marked as wontfix. This may be fixed in the future.

References (8)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner elastic
Published Jul 27, 2020
Updated Aug 4, 2024
Reserved Jan 14, 2020

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Jul 27, 2020
Bugzilla 1865760

ENISA EUVD

Assigner elastic
Published Jul 27, 2020
Updated Aug 4, 2024

GitHub

No data