kibana: cross-site-scripting (XSS) issue (ESA-2022-04)
Published Mar 3, 2022
6.1
MEDIUMCVSS 3.1
EPSS 0.77%
Description
A cross-site-scripting (XSS) vulnerability was discovered in the Data Preview Pane (previously known as Index Pattern Preview Pane) which could allow arbitrary JavaScript to be executed in a victim’s browser.
Affected products
-
- Version For self-managed deployments the issue impacts versions 7.15.0, 7.15.1, and 7.15.2 For Elastic Cloud Services the issue impacts versions 7.15.0 through 7.17.0, and 8.0.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
Logging Subsystem for Red Hat OpenShift
openshift-logging/elasticsearch-rhel8-operator
Will not fix
Logging Subsystem for Red Hat OpenShift
openshift-logging/kibana6-rhel8
Will not fix
Red Hat JBoss Fuse 6
Kibana
Out of support scope
Red Hat JBoss Fuse Service Works 6
Kibana
Out of support scope
Red Hat OpenShift Container Platform 3.11
kibana
Will not fix
Red Hat OpenShift Container Platform 3.11
openshift3/ose-logging-kibana5
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/ose-elasticsearch-operator
Fix deferred
Red Hat OpenShift Container Platform 4
openshift4/ose-logging-kibana6
Fix deferred
Red Hat OpenStack Platform 13 (Queens)
puppet-kibana3
Out of support scope
Red Hat OpenStack Platform 16.1
puppet-kibana3
Will not fix
Red Hat OpenStack Platform 16.2
puppet-kibana3
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Logging Subsystem for Red Hat OpenShift | openshift-logging/elasticsearch-rhel8-operator | Will not fix | n/a |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/kibana6-rhel8 | Will not fix | n/a |
| Red Hat JBoss Fuse 6 | Kibana | Out of support scope | n/a |
| Red Hat JBoss Fuse Service Works 6 | Kibana | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.11 | kibana | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.11 | openshift3/ose-logging-kibana5 | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-elasticsearch-operator | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-logging-kibana6 | Fix deferred | n/a |
| Red Hat OpenStack Platform 13 (Queens) | puppet-kibana3 | Out of support scope | n/a |
| Red Hat OpenStack Platform 16.1 | puppet-kibana3 | Will not fix | n/a |
| Red Hat OpenStack Platform 16.2 | puppet-kibana3 | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://access.redhat.com/security/cve/CVE-2022-23710 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2066387 Issue Tracking
- https://discuss.elastic.co/t/elastic-stack-7-17-1-security-update/298447 x_refsource_MISCRelease NotesVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1469 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-23710
- https://security.netapp.com/advisory/ntap-20220325-0009/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-23710
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-23710 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2066387 | Issue Tracking | |
| https://discuss.elastic.co/t/elastic-stack-7-17-1-security-update/298447 | x_refsource_MISCRelease NotesVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1469 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-23710 | ||
| https://security.netapp.com/advisory/ntap-20220325-0009/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-23710 |
Change history (0)
No recorded changes yet.