CVE-2020-7015

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
03/06/2020
Last modified:
19/10/2020

Description

Kibana versions before 6.8.9 and 7.7.0 contains a stored XSS flaw in the TSVB visualization. An attacker who is able to edit or create a TSVB visualization could allow the attacker to obtain sensitive information from, or perform destructive actions, on behalf of Kibana users who edit the TSVB visualization.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:* 6.8.10 (excluding)
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:* 7.0.0 (including) 7.7.1 (excluding)


References to Advisories, Solutions, and Tools