CVE-2021-22136

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/05/2021
Last modified:
21/05/2021

Description

In Kibana versions before 7.12.0 and 6.8.15 a flaw in the session timeout was discovered where the xpack.security.session.idleTimeout setting is not being respected. This was caused by background polling activities unintentionally extending authenticated users sessions, preventing a user session from timing out.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:* 6.8.15 (excluding)
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:* 7.0.0 (including) 7.12.0 (excluding)