Impact
In Kibana, an incomplete list of disallowed inputs—identified in the description as CWE‑184 and classified by the vendor as CWE‑863 (Server‑Side Request Forgery)—allows an authenticated attacker who can use the Reporting feature to bypass administrator‑configured outbound request restrictions. The attacker can cause the reporting service to send requests to previously blocked internal or external network destinations, potentially exfiltrating data or enabling further lateral movement.
Affected Systems
Elastic Kibana is affected. All currently deployed instances without the fix may be vulnerable until upgraded.
Risk and Exploitability
The CVSS score of 5 indicates a medium severity impact. The EPSS score of less than 1% suggests a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated and have Reporting feature permissions; therefore, restricting that role or disabling Reporting can reduce the risk.
OpenCVE Enrichment