Lucene search

K
cvelistElasticCVELIST:CVE-2018-3818
HistoryMar 30, 2018 - 8:00 p.m.

CVE-2018-3818

2018-03-3020:00:00
CWE-79
elastic
www.cve.org
2

0.001 Low

EPSS

Percentile

32.7%

Kibana versions 5.1.1 to 6.1.2 and 5.6.6 had a cross-site scripting (XSS) vulnerability via the colored fields formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

CNA Affected

[
  {
    "product": "Kibana",
    "vendor": "Elastic",
    "versions": [
      {
        "status": "affected",
        "version": "5.1.1 to 6.1.2 and 5.6.6"
      }
    ]
  }
]

0.001 Low

EPSS

Percentile

32.7%

Related for CVELIST:CVE-2018-3818