In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive information or perform destructive actions on behalf of Kibana users who view the region map visualization.
References
Link | Resource |
---|---|
https://www.elastic.co/community/security/ | Vendor Advisory |
https://discuss.elastic.co/t/elastic-stack-6-8-11-and-7-8-1-security-update/242786 | Release Notes Vendor Advisory |
https://www.oracle.com//security-alerts/cpujul2021.html | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2020-07-27 11:15
Updated : 2022-10-07 10:56
NVD link : CVE-2020-7017
Mitre link : CVE-2020-7017
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
oracle
- peoplesoft_enterprise_peopletools
- communications_billing_and_revenue_management
- communications_cloud_native_core_network_function_cloud_native_environment
elasticsearch
- kibana