7.2
CVSSv3

CVE-2021-22150

Published: 22/11/2023 Updated: 01/12/2023
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

It exists that a user with Fleet admin permissions could upload a malicious package. Due to using an older version of the js-yaml library, this package would be loaded in an insecure manner, allowing an malicious user to execute commands on the Kibana server.

Vulnerable Product Search on Vulmon Subscribe to Product

elastic kibana

Vendor Advisories

A security issue has been found in kibana before version 7141 It was discovered that a user with fleet admin permissions could upload a malicious package Due to using an older version of the js-yaml library, this package would be loaded in an insecure manner, allowing an attacker to execute commands on the kibana server ...