CVE-2021-37939

LOW

Kibana 7.8.0-7.15.1 - Authenticated Internal Host HTTP Response Disclosure via JIRA and IBM Resilient Connectors

Title source: llm
STIX 2.1

Description

It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, which may be intentionally hidden from public view. Using this vulnerability, a malicious user with the ability to create connectors, could utilize these connectors to view limited HTTP response data on hosts accessible to the cluster.

References (1)

Core 1
Core References

Scores

CVSS v3 2.7
EPSS 0.0011
EPSS Percentile 28.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-319 CWE-200
Status published
Products (2)
elastic/kibana 7.8.0 - 7.15.2
npm/kibana 7.8.0 - 7.15.2npm
Published Nov 18, 2021
Tracked Since Feb 18, 2026