Kibana: Cross-site scripting issue (ESA-2022-01)
Published Feb 11, 2022
8.1
HIGHCVSS 3.1
EPSS 0.53%
Description
An XSS vulnerability was found in Kibana index patterns. Using this vulnerability, an authenticated user with permissions to create index patterns can inject malicious javascript into the index pattern which could execute against other users
Affected products
-
- Version 7.5.1 through 7.16.3StatusaffectedConstraints-
- Version
No data.
Logging Subsystem for Red Hat OpenShift
openshift-logging/elasticsearch-rhel8-operator
Will not fix
Logging Subsystem for Red Hat OpenShift
openshift-logging/kibana6-rhel8
Will not fix
Red Hat JBoss Fuse 6
Kibana
Out of support scope
Red Hat JBoss Fuse Service Works 6
Kibana
Out of support scope
Red Hat OpenShift Container Platform 3.11
kibana
Will not fix
Red Hat OpenShift Container Platform 3.11
openshift3/ose-logging-kibana5
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/ose-elasticsearch-operator
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/ose-logging-kibana6
Will not fix
Red Hat OpenStack Platform 13 (Queens)
puppet-kibana3
Out of support scope
Red Hat OpenStack Platform 16.1
puppet-kibana3
Not affected
Red Hat OpenStack Platform 16.2
puppet-kibana3
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Logging Subsystem for Red Hat OpenShift | openshift-logging/elasticsearch-rhel8-operator | Will not fix | n/a |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/kibana6-rhel8 | Will not fix | n/a |
| Red Hat JBoss Fuse 6 | Kibana | Out of support scope | n/a |
| Red Hat JBoss Fuse Service Works 6 | Kibana | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.11 | kibana | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.11 | openshift3/ose-logging-kibana5 | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-elasticsearch-operator | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-logging-kibana6 | Will not fix | n/a |
| Red Hat OpenStack Platform 13 (Queens) | puppet-kibana3 | Out of support scope | n/a |
| Red Hat OpenStack Platform 16.1 | puppet-kibana3 | Not affected | n/a |
| Red Hat OpenStack Platform 16.2 | puppet-kibana3 | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://access.redhat.com/security/cve/CVE-2022-23707 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2051419 Issue Tracking
- https://discuss.elastic.co/t/kibana-7-17-0-security-update/296215 x_refsource_MISCPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-23707
- https://www.cve.org/CVERecord?id=CVE-2022-23707
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-23707 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2051419 | Issue Tracking | |
| https://discuss.elastic.co/t/kibana-7-17-0-security-update/296215 | x_refsource_MISCPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-23707 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-23707 |
Change history (0)
No recorded changes yet.