Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22213
HistoryDec 20, 2019 - 3:43 a.m.

Cross-Site Scripting (XSS)

2019-12-2003:43:44
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.001 Low

EPSS

Percentile

22.7%

kibana is vulnerable to cross-site scripting (XSS). Lack of validation and sanitization in the coordinate and region map visualizations allows a remote attacker to inject arbitrary Javascript into a user’s browser via the options attribution settings.

CPENameOperatorVersion
kibanale6.8.5
kibanale7.5.0

0.001 Low

EPSS

Percentile

22.7%