File Upload Vulnerability in Kibana by Elastic
CVE-2024-11390

5.4MEDIUM

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
1 May 2025

What is CVE-2024-11390?

A vulnerability in Kibana allows for the unrestricted upload of files that can contain malicious HTML and JavaScript. This can result in arbitrary JavaScript being executed in the browser of users interacting with the affected Kibana instance. For exploitation, the attacker must possess access to the Synthetics app and/or the ability to write to the synthetics indices, making it crucial for users to review their access controls and monitor for any suspicious activities.

Affected Version(s)

Kibana 7.17.6 < 7.17.23

Kibana 8.4.0 < 8.11.4

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-11390 : File Upload Vulnerability in Kibana by Elastic