CVE-2018-3821
30.03.2018, 20:29
Kibana versions after 5.1.1 and before 5.6.7 and 6.1.3 had a cross-site scripting (XSS) vulnerability in the tag cloud visualization that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
Vendor | Product | Version |
---|---|---|
elastic | kibana | 5.1.1 < 𝑥 < 5.6.7 |
elastic | kibana | 6.0.0 ≤ 𝑥 < 6.1.3 |
𝑥
= Vulnerable software versions