CVE-2021-37936

MEDIUM

Kibana < 7.14.1 - Stored Cross-Site Scripting via Discover App Search Highlighting

Title source: llm
STIX 2.1

Description

It was discovered that Kibana was not sanitizing document fields containing HTML snippets. Using this vulnerability, an attacker with the ability to write documents to an elasticsearch index could inject HTML. When the Discover app highlighted a search term containing the HTML, it would be rendered for the user.

References (2)

Core 2

Scores

CVSS v3 5.4
EPSS 0.0056
EPSS Percentile 68.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
elastic/kibana < 7.14.1
Published Nov 18, 2022
Tracked Since Feb 18, 2026