CVE-2017-8440
05.06.2017, 14:29
Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
Vendor | Product | Version |
---|---|---|
elastic | kibana | 5.3.0 |
elastic | kibana | 5.3.1 |
elastic | kibana | 5.3.2 |
elastic | kibana | 5.4.0 |
𝑥
= Vulnerable software versions
References