CVE-2016-1000220
medium
CVSS v3
6.1
CVSS v2
4.3
VIR risk
6.1
Description
Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScript in users' browsers.
Predictions
Exploit likelihood
71%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — https://www.elastic.co/community/security
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| elastic | kibana | {"startIncluding":"4.1.0","endExcluding":"4.1.11"} | 4.1.11 |
References
CWEs
CWE-79
Verify integrity in audit chain (admin only). AS-IS.