kibana: stored XSS in region map visualization
Published Jul 27, 2020
6.7
MEDIUMCVSS 3.1
EPSS 1.22%
Description
In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive information or perform destructive actions on behalf of Kibana users who view the region map visualization.
Affected products
-
Affected
- before 6.8.11 and 7.8.1
Configuration 1
- < 6.8.11
- ≥ 7.0.0 · < 7.8.1
Configuration 2
- 12.0.0.3.0
- 1.7.0
- 8.58
No data.
Red Hat OpenShift Container Platform 3.11
kibana
Fix deferred
Red Hat OpenShift Container Platform 4
kibana
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/ose-logging-kibana6
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | kibana | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | kibana | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-logging-kibana6 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
In Red Hat OpenShift Container Platform (RHOCP) the affected kibana region map visualization is behind OpenShift OAuth authentication. This restricts access to the vulnerable visualization to authenticated users only, therefore the impact is Low. Red Hat OpenShift Container Platform 4 delivers the kibana package where the region map visualization is included, but due to the code changing to the container first content, the kibana package is marked as wontfix. This may be fixed in the future.
References (8)
- https://access.redhat.com/security/cve/CVE-2020-7017 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1865760 Issue Tracking
- https://discuss.elastic.co/t/elastic-stack-6-8-11-and-7-8-1-security-update/242786 x_refsource_MISCRelease NotesVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-28154 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-7017
- https://www.cve.org/CVERecord?id=CVE-2020-7017
- https://www.elastic.co/community/security/ x_refsource_MISCVendor Advisory
- https://www.oracle.com//security-alerts/cpujul2021.html x_refsource_MISCThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-7017 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1865760 | Issue Tracking | |
| https://discuss.elastic.co/t/elastic-stack-6-8-11-and-7-8-1-security-update/242786 | x_refsource_MISCRelease NotesVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-28154 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-7017 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-7017 | ||
| https://www.elastic.co/community/security/ | x_refsource_MISCVendor Advisory | |
| https://www.oracle.com//security-alerts/cpujul2021.html | x_refsource_MISCThird Party Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data