CVE-2017-8439

MEDIUM

Elastic Kibana - XSS

Title source: rule

Description

Kibana version 5.4.0 was affected by a Cross Site Scripting (XSS) bug in the Time Series Visual Builder. This bug could allow an attacker to obtain sensitive information from Kibana users.

Scores

CVSS v3 6.1
EPSS 0.0034
EPSS Percentile 56.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
elastic/kibana
Elastic/Kibana < 5.4.0
Published Jun 05, 2017
Tracked Since Feb 18, 2026