CVE-2022-23711
MEDIUMKibana 7.2.1-7.17.2 - Unauthenticated Exposure of Sensitive Information in Page Source
Title source: llmDescription
A vulnerability in Kibana could expose sensitive information related to Elastic Stack monitoring in the Kibana page source. Elastic Stack monitoring features provide a way to keep a pulse on the health and performance of your Elasticsearch cluster. Authentication with a vulnerable Kibana instance is not required to view the exposed information. The Elastic Stack monitoring exposure only impacts users that have set any of the optional monitoring.ui.elasticsearch.* settings in order to configure Kibana as a remote UI for Elastic Stack Monitoring. The same vulnerability in Kibana could expose other non-sensitive application-internal information in the page source.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_misc
https://discuss.elastic.co/t/kibana-7-17-3-and-8-1-3-security-update/302826
Scores
CVSS v3
5.3
EPSS
0.0022
EPSS Percentile
44.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-200
Status
published
Products (1)
elastic/kibana
7.2.1 - 7.17.3
Published
Apr 21, 2022
Tracked Since
Feb 18, 2026