Kibana contains an embedded version of the Chromium browser that the Reporting feature uses to generate the downloadable reports. If a user with permissions to generate reports is able to render arbitrary HTML with this browser, they may be able to leverage known Chromium vulnerabilities to conduct further attacks. Kibana contains a number of protections to prevent this browser from rendering arbitrary content.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-9293 Kibana contains an embedded version of the Chromium browser that the Reporting feature uses to generate the downloadable reports. If a user with permissions to generate reports is able to render arbitrary HTML with this browser, they may be able to leverage known Chromium vulnerabilities to conduct further attacks. Kibana contains a number of protections to prevent this browser from rendering arbitrary content.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2024-08-03T18:37:17.271Z

Reserved: 2021-01-04T20:17:39.856Z

Link: CVE-2021-22142

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-11-22T01:15:07.210

Modified: 2024-11-21T05:49:35.293

Link: CVE-2021-22142

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-05-25T00:00:00Z

Links: CVE-2021-22142 - Bugzilla

cve-icon OpenCVE Enrichment

No data.