Vulnerabilities > Elastic > Kibana > 7.11.0

DATE CVE VULNERABILITY TITLE RISK
2022-02-11 CVE-2022-23707 Cross-site Scripting vulnerability in Elastic Kibana
An XSS vulnerability was found in Kibana index patterns.
network
elastic CWE-79
3.5
2021-11-18 CVE-2021-37938 Path Traversal vulnerability in Elastic Kibana
It was discovered that on Windows operating systems specifically, Kibana was not validating a user supplied path, which would load .pbf files.
network
low complexity
elastic CWE-22
4.0
2021-11-18 CVE-2021-37939 Cleartext Transmission of Sensitive Information vulnerability in Elastic Kibana
It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, which may be intentionally hidden from public view.
network
low complexity
elastic CWE-319
4.0
2021-05-13 CVE-2021-22136 Insufficient Session Expiration vulnerability in Elastic Kibana
In Kibana versions before 7.12.0 and 6.8.15 a flaw in the session timeout was discovered where the xpack.security.session.idleTimeout setting is not being respected.
local
low complexity
elastic CWE-613
3.6
2021-05-13 CVE-2021-22139 Resource Exhaustion vulnerability in Elastic Kibana
Kibana versions before 7.12.1 contain a denial of service vulnerability was found in the webhook actions due to a lack of timeout or a limit on the request size.
network
low complexity
elastic CWE-400
4.0