CVE-2022-38778

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
08/02/2023
Last modified:
25/03/2025

Description

A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a request that crashes the Kibana server process.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:decode-uri-component_project:decode-uri-component:*:*:*:*:*:node.js:*:* 0.2.1 (excluding)
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:* 7.0.0 (including) 7.17.9 (excluding)
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:* 8.0.0 (including) 8.6.1 (excluding)