kibana: xpack.security.session.idleTimeout setting timeout not being respected
Published May 13, 2021
4.0
MEDIUMCVSS 3.1
EPSS 0.28%
Description
In Kibana versions before 7.12.0 and 6.8.15 a flaw in the session timeout was discovered where the xpack.security.session.idleTimeout setting is not being respected. This was caused by background polling activities unintentionally extending authenticated users sessions, preventing a user session from timing out.
Affected products
-
- Version before 7.12.0 and 6.8.15StatusaffectedConstraints-
- Version
No data.
Logging Subsystem for Red Hat OpenShift
openshift-logging/kibana6-rhel8
Not affected
Red Hat OpenShift Container Platform 3.11
kibana
Not affected
Red Hat OpenShift Container Platform 4
kibana
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-logging-kibana6
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Logging Subsystem for Red Hat OpenShift | openshift-logging/kibana6-rhel8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | kibana | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | kibana | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-logging-kibana6 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
In OpenShift Container Platform (OCP) the kibana components have X-Pack security features disabled by default. The X-Pack plugin can be used only is an enterprise version [1]. Hence the open source version is unaffected by this vulnerability. [1] https://www.elastic.co/subscriptions
References (5)
- https://access.redhat.com/security/cve/CVE-2021-22136 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1943200 Issue Tracking
- https://discuss.elastic.co/t/elastic-stack-7-12-0-and-6-8-15-security-update/268125 x_refsource_MISCVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-22136
- https://www.cve.org/CVERecord?id=CVE-2021-22136
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2021-22136 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1943200 | Issue Tracking | |
| https://discuss.elastic.co/t/elastic-stack-7-12-0-and-6-8-15-security-update/268125 | x_refsource_MISCVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2021-22136 | ||
| https://www.cve.org/CVERecord?id=CVE-2021-22136 |
Change history (0)
No recorded changes yet.