Meet Corgea at Black Hat, BSides Las Vegas & DEF CON
MEDIUM 6.1 Maven

Withdrawn: Cross-site Scripting in Kibana

GHSA-m6gg-86c6-gfr9

Published · Modified

Description

##Withdrawn: This advisory is for Kibana, not ElasticSearch as it was originally published, and is withdrawn as being out of scope of our supported ecosystems.

A cross-site-scripting (XSS) vulnerability was discovered in the Data Preview Pane (previously known as Index Pattern Preview Pane) which could allow arbitrary JavaScript to be executed in a victim's browser.

Ready to move

Start Securing

Free, no credit card | First findings in minutes