ZeroHour

CVE-2017-11479

CVSS 3.0
6.1 medium
EPSS
1%p63
Published
()
Modified
Description

Kibana versions prior to 5.6.1 had a cross-site scripting (XSS) vulnerability in Timelion that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

Vendors
elasticelasticsearch
Products
kibana
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.