[MAVEN:GHSA-M6GG-86C6-GFR9] Withdrawn: Cross-site Scripting in Kibana

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

##Withdrawn: This advisory is for Kibana, not ElasticSearch as it was originally published, and is withdrawn as being out of scope of our supported ecosystems.

A cross-site-scripting (XSS) vulnerability was discovered in the Data Preview Pane (previously known as Index Pattern Preview Pane) which could allow arbitrary JavaScript to be executed in a victim's browser.

Package Affected Version
pkg:maven/org.elasticsearch/elasticsearch >= 7.16.0, < 7.17.1
Package Fixed Version
pkg:maven/org.elasticsearch/elasticsearch = 7.17.1
ID
MAVEN:GHSA-M6GG-86C6-GFR9
Severity
moderate
URL
https://github.com/advisories/GHSA-m6gg-86c6-gfr9
Published
2022-03-04T00:00:15
(2 years ago)
Modified
2023-03-15T19:19:14
(18 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.elasticsearch/elasticsearch org.elasticsearch elasticsearch >= 7.16.0 < 7.17.1
Fixed pkg:maven/org.elasticsearch/elasticsearch org.elasticsearch elasticsearch = 7.17.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...