CVE-2017-8440

MEDIUM

Elastic Kibana - XSS

Title source: rule

Description

Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

Scores

CVSS v3 6.1
EPSS 0.0034
EPSS Percentile 56.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (6)
elastic/kibana
elastic/kibana
elastic/kibana
elastic/kibana
Elastic/Kibana < 5.3.0 to 5.3.3
Elastic/Kibana < 5.4.1
Published Jun 05, 2017
Tracked Since Feb 18, 2026