Bug 1789953 (CVE-2019-7621) - CVE-2019-7621 kibana: XSS in the coordinate and region map visualizations (ESA-2019-17)
Summary: CVE-2019-7621 kibana: XSS in the coordinate and region map visualizations (ES...
Keywords:
Status: NEW
Alias: CVE-2019-7621
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 1790764 1790765 1790766 1790767 1790768
Blocks: 1789955
TreeView+ depends on / blocked
 
Reported: 2020-01-10 20:03 UTC by Guilherme de Almeida Suckevicz
Modified: 2023-07-07 08:28 UTC (History)
6 users (show)

Fixed In Version: kibana 7.5.1, kibana 6.8.6
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Guilherme de Almeida Suckevicz 2020-01-10 20:03:06 UTC
Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with the ability to create coordinate map visualizations could create a malicious visualization. If another Kibana user views that visualization or a dashboard containing the visualization it could execute JavaScript in the victim?s browser.

References:
https://discuss.elastic.co/t/elastic-stack-6-8-6-and-7-5-1-security-update/212390
https://www.elastic.co/community/security/


Note You need to log in before you can comment on or make changes to this bug.