CVE-2022-23711
Dashboard / Vulnerabilities / CVE-2022-23711
CVE-2022-23711
Summary:
Details: A vulnerability in Kibana could expose sensitive information related to Elastic Stack monitoring in the Kibana page source. Elastic Stack monitoring features provide a way to keep a pulse on the health and performance of your Elasticsearch cluster. Authentication with a vulnerable Kibana instance is not required to view the exposed information. The Elastic Stack monitoring exposure only impacts users that have set any of the optional monitoring.ui.elasticsearch.* settings in order to configure Kibana as a remote UI for Elastic Stack Monitoring. The same vulnerability in Kibana could expose other non-sensitive application-internal information in the page source.
References: https://discuss.elastic.co/t/kibana-7-17-3-and-8-1-3-security-update/302826, https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23711.json, https://nvd.nist.gov/vuln/detail/CVE-2022-23711
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
