Kibana Insertion of Sensitive Information into Log File
CVE-2023-31422
7.5HIGH
Summary
A vulnerability has been identified in Elastic Kibana, where sensitive user information may be unintentionally recorded in logs during error events. This issue specifically affects Kibana version 8.10.0, particularly when utilizing JSON logging and certain pattern configurations that incorporate the %meta pattern. The logged error objects may include highly sensitive data such as authentication credentials, cookies, authorization headers, and query parameters, potentially revealing account details for users such as kibana_system and kibana-metricbeat. To mitigate this risk, users are advised to upgrade to Kibana 8.10.1, which addresses this logging issue.
Affected Version(s)
Kibana 8.10.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved