VulnerabilityModified
CVE-2018-3818
Kibana versions 5.1.1 to 6.1.2 and 5.6.6 had a cross-site scripting (XSS) vulnerability via the colored fields formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
MEDIUM 6.1EPSS 1.03%
Does this matter?
Lower severity and a low EPSS score (1.03%). Track it; it rarely justifies an emergency change on its own.
Description
Kibana versions 5.1.1 to 6.1.2 and 5.6.6 had a cross-site scripting (XSS) vulnerability via the colored fields formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.03% probability · 62th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- elastic/kibana
- Source
- security@elastic.co
References
- http://www.securityfocus.com/bid/102734Third Party Advisory, VDB Entry
- https://discuss.elastic.co/t/elastic-stack-6-1-2-and-5-6-6-security-update/115763Vendor Advisory
- http://www.securityfocus.com/bid/102734Third Party Advisory, VDB Entry
- https://discuss.elastic.co/t/elastic-stack-6-1-2-and-5-6-6-security-update/115763Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.