Kibana path traversal issue
CVE-2021-22151

3.1LOW

Key Information:

Vendor
Elastic
Status
Vendor
CVE Published:
22 November 2023

Summary

It was discovered that Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host to load internal files ending in the .pbf extension.

Affected Version(s)

Kibana 7.9.0 < 7.14.0

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.