Vulnerabilities > Elastic > Kibana > High

DATE CVE VULNERABILITY TITLE RISK
2024-09-09 CVE-2024-37288 Deserialization of Untrusted Data vulnerability in Elastic Kibana 8.15.0
A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload.
network
low complexity
elastic CWE-502
8.8
2024-08-13 CVE-2024-37287 Unspecified vulnerability in Elastic Kibana
A flaw allowing arbitrary code execution was discovered in Kibana.
network
low complexity
elastic
7.2
2023-11-22 CVE-2021-22142 Unspecified vulnerability in Elastic Kibana
Kibana contains an embedded version of the Chromium browser that the Reporting feature uses to generate the downloadable reports.
network
low complexity
elastic
8.8
2023-11-22 CVE-2021-22150 Code Injection vulnerability in Elastic Kibana
It was discovered that a user with Fleet admin permissions could upload a malicious package.
network
low complexity
elastic CWE-94
7.2
2023-10-26 CVE-2023-31422 Information Exposure Through Log Files vulnerability in Elastic Kibana 8.10.0
An issue was discovered by Elastic whereby sensitive information is recorded in Kibana logs in the event of an error.
network
low complexity
elastic CWE-532
7.5
2023-05-04 CVE-2023-31414 Code Injection vulnerability in Elastic Kibana
Kibana versions 8.0.0 through 8.7.0 contain an arbitrary code execution flaw.
network
low complexity
elastic CWE-94
8.8
2023-05-04 CVE-2023-31415 Code Injection vulnerability in Elastic Kibana 8.7.0
Kibana version 8.7.0 contains an arbitrary code execution flaw.
network
low complexity
elastic CWE-94
8.8
2020-06-03 CVE-2020-7013 Code Injection vulnerability in multiple products
Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB.
network
low complexity
elastic redhat CWE-94
7.2
2020-06-03 CVE-2020-7012 Code Injection vulnerability in Elastic Kibana
Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant.
network
low complexity
elastic CWE-94
8.8
2017-06-16 CVE-2017-8452 Uncontrolled File Descriptor Consumption vulnerability in Elastic Kibana
Kibana versions prior to 5.2.1 configured for SSL client access, file descriptors will fail to be cleaned up after certain requests and will accumulate over time until the process crashes.
network
low complexity
elastic CWE-769
7.5