CVE-2017-8439
MEDIUMElastic Kibana - XSS
Title source: ruleDescription
Kibana version 5.4.0 was affected by a Cross Site Scripting (XSS) bug in the Time Series Visual Builder. This bug could allow an attacker to obtain sensitive information from Kibana users.
Scores
CVSS v3
6.1
EPSS
0.0034
EPSS Percentile
56.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
elastic/kibana
Elastic/Kibana
< 5.4.0
Published
Jun 05, 2017
Tracked Since
Feb 18, 2026