CVE-2021-22142
Dashboard / Vulnerabilities / CVE-2021-22142
CVE-2021-22142
Published: 22 Nov 2023Last Modified: 8 Jul 2026
Summary:
Details: Kibana contains an embedded version of the Chromium browser that the Reporting feature uses to generate the downloadable reports. If a user with permissions to generate reports is able to render arbitrary HTML with this browser, they may be able to leverage known Chromium vulnerabilities to conduct further attacks. Kibana contains a number of protections to prevent this browser from rendering arbitrary content.
References: https://discuss.elastic.co/t/elastic-stack-7-13-0-and-6-8-16-security-update/273964/1, https://www.elastic.co/community/security
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- b7e28a7232616c7a21bc879a535d801b8553ba77
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
