In Kibana versions before 7.12.0 and 6.8.15 a flaw in the session timeout was discovered where the xpack.security.session.idleTimeout setting is not being respected. This was caused by background polling activities unintentionally extending authenticated users sessions, preventing a user session from timing out.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: elastic
Published: 2021-05-13T17:35:17
Updated: 2024-08-03T18:30:23.975Z
Reserved: 2021-01-04T00:00:00
Link: CVE-2021-22136
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-05-13T18:15:08.993
Modified: 2024-11-21T05:49:34.560
Link: CVE-2021-22136
Redhat