320
VMScore

CVE-2021-22136

Published: 13/05/2021 Updated: 21/05/2021
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 3.5 | Impact Score: 2.5 | Exploitability Score: 0.9
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

In Kibana versions prior to 7.12.0 and 6.8.15 a flaw in the session timeout exists where the xpack.security.session.idleTimeout setting is not being respected. This was caused by background polling activities unintentionally extending authenticated users sessions, preventing a user session from timing out.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

Vendor Advisories

A flaw in Kibana versions before 7120 and 6815 was discovered where the xpacksecuritysessionidleTimeout setting is not being respected This was caused by background polling activities unintentionally extending authenticated users sessions, preventing a user session from timing out ...