Bug 2148121 (CVE-2021-37936) - CVE-2021-37936 kibana: HTML injection issue (ESA-2021-23)
Summary: CVE-2021-37936 kibana: HTML injection issue (ESA-2021-23)
Keywords:
Status: CLOSED WONTFIX
Alias: CVE-2021-37936
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2144437
TreeView+ depends on / blocked
 
Reported: 2022-11-24 12:57 UTC by Avinash Hanwate
Modified: 2022-12-08 03:32 UTC (History)
18 users (show)

Fixed In Version: kibana 7.14.1
Doc Type: ---
Doc Text:
A flaw was found in Kibana. This issue occurs due to Kibana not sanitizing document fields containing HTML snippets. An attacker with the ability to write documents to an elasticsearch index could inject HTML. When the Discover app highlighted a search term containing the HTML, it would be rendered for the user.
Clone Of:
Environment:
Last Closed: 2022-12-08 03:32:50 UTC
Embargoed:


Attachments (Terms of Use)

Description Avinash Hanwate 2022-11-24 12:57:56 UTC
It was discovered that Kibana was not sanitizing document fields containing HTML snippets. Using this vulnerability, an attacker with the ability to write documents to an elasticsearch index could inject HTML. When the Discover app highlighted a search term containing the HTML, it would be rendered for the user.

https://www.elastic.co/community/security/
https://discuss.elastic.co/t/elastic-stack-7-14-1-security-update/283077

Comment 1 Product Security DevOps Team 2022-12-08 03:32:48 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2021-37936


Note You need to log in before you can comment on or make changes to this bug.