CVE-2021-22136

LOW

Kibana < 6.8.15 - Insufficient Session Expiration via Background Polling

Title source: llm
STIX 2.1

Description

In Kibana versions before 7.12.0 and 6.8.15 a flaw in the session timeout was discovered where the xpack.security.session.idleTimeout setting is not being respected. This was caused by background polling activities unintentionally extending authenticated users sessions, preventing a user session from timing out.

References (1)

Core 1

Scores

CVSS v3 3.5
EPSS 0.0005
EPSS Percentile 15.5%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-613
Status published
Products (1)
elastic/kibana < 6.8.15
Published May 13, 2021
Tracked Since Feb 18, 2026