5.4
CVSSv3

CVE-2021-37936

Published: 18/11/2022 Updated: 22/11/2022
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

It exists that Kibana was not sanitizing document fields containing HTML snippets. Using this vulnerability, an attacker with the ability to write documents to an elasticsearch index could inject HTML. When the Discover app highlighted a search term containing the HTML, it would be rendered for the user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

elastic kibana

Vendor Advisories

Description<!---->A flaw was found in Kibana This issue occurs due to Kibana not sanitizing document fields containing HTML snippets An attacker with the ability to write documents to an elasticsearch index could inject HTML When the Discover app highlighted a search term containing the HTML, it would be rendered for the userA flaw was found in ...
A security issue has been found in kibana before version 7141 It was discovered that kibana was not sanitizing document fields containing html snippets Using this vulnerability, an attacker with the ability to write documents to an elasticsearch index could inject HTML When the Discover app highlighted a search term containing the HTML, it wou ...