Lucene search

K
cvelistElasticCVELIST:CVE-2020-7015
HistoryJun 03, 2020 - 5:55 p.m.

CVE-2020-7015

2020-06-0317:55:44
CWE-79
elastic
www.cve.org

5.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.7%

Kibana versions before 6.8.9 and 7.7.0 contains a stored XSS flaw in the TSVB visualization. An attacker who is able to edit or create a TSVB visualization could allow the attacker to obtain sensitive information from, or perform destructive actions, on behalf of Kibana users who edit the TSVB visualization.

CNA Affected

[
  {
    "product": "Kibana",
    "vendor": "Elastic",
    "versions": [
      {
        "status": "affected",
        "version": "before 6.8.9 and 7.7.0"
      }
    ]
  }
]

5.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.7%