CVE-2021-22150
Dashboard / Vulnerabilities / CVE-2021-22150
CVE-2021-22150
Published: 22 Nov 2023Last Modified: 9 Jul 2026
Summary:
Details: It was discovered that a user with Fleet admin permissions could upload a malicious package. Due to using an older version of the js-yaml library, this package would be loaded in an insecure manner, allowing an attacker to execute commands on the Kibana server.
References: https://discuss.elastic.co/t/elastic-stack-7-14-1-security-update/283077, https://www.elastic.co/community/security
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 747e1cc71def077253878a59143c1f785afa92b9
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
