Kibana code execution issue
CVE-2021-22150
6.6MEDIUM
What is CVE-2021-22150?
It was discovered that a user with Fleet admin permissions could upload a malicious package. Due to using an older version of the js-yaml library, this package would be loaded in an insecure manner, allowing an attacker to execute commands on the Kibana server.
Affected Version(s)
Kibana 7.10.2 < 7.14.0