Exposición de Kibana

JavaScript graphics, Search engines
78
score de exposición
6
sitios usan
1
en explotación
8
críticos
Análisis Vexday

Com 107 CVEs catalogadas, o Kibana apresenta taxa de exploração ativa 2,1 vezes acima da média geral do catálogo CISA KEV, o que indica uma superfície de ataque com histórico real de abuso, não apenas risco teórico. A CVE mais perigosa em exploração ativa é a CVE-2019-7609, com score EPSS de 0,95, sinalizando altíssima probabilidade de tentativas de exploração em ambientes expostos. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), relevante em ferramentas de visualização onde interfaces web são parte central da funcionalidade. O surgimento de 15 novas CVEs nos últimos 90 dias, combinado com 8 de severidade crítica, reforça a necessidade de manter o Kibana atualizado e com acesso devidamente restrito.

CVEs

186 resultados
CVE-2020-10743—It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercEPSS 0.7%CVE-2019-7621—Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attackeEPSS 0.7%CVE-2021-22151LOWKibana path traversal issueEPSS 0.7%CVE-2023-46675HIGHKibana Insertion of Sensitive Information into Log FileEPSS 0.7%CVE-2023-46671HIGHKibana Insertion of Sensitive Information into Log FileEPSS 0.7%CVE-2023-31414HIGHKibana versions 8.0.0 through 8.7.0 contain an arbitrary code execution flaw. An attacker with write access to Kibana yaml or env configuratEPSS 0.6%CVE-2021-22141MEDIUMAn open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously crafted URL, it could EPSS 0.6%CVE-2022-23709—A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A user with this privilegEPSS 0.6%CVE-2024-12556HIGHKibana Prototype Pollution can lead to code injectionEPSS 0.5%CVE-2022-23707—An XSS vulnerability was found in Kibana index patterns. Using this vulnerability, an authenticated user with permissions to create index paEPSS 0.5%CVE-2026-26936MEDIUMInefficient Regular Expression Complexity in Kibana Leading to Denial of ServiceEPSS 0.5%CVE-2026-72660MEDIUMUncaught Exception in Kibana Leading to Denial of ServiceEPSS 0.5%CVE-2022-38779—An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciouslyEPSS 0.5%CVE-2026-72654MEDIUMExecution with Unnecessary Privileges in Kibana Leading to Information DisclosureEPSS 0.5%CVE-2026-63137HIGHIncorrect Authorization in Kibana Leading to Privilege EscalationEPSS 0.5%CVE-2024-23446MEDIUMKibana Broken Access Control issueEPSS 0.5%CVE-2026-4498HIGHExecution with Unnecessary Privileges in Kibana Leading to reading index data beyond their direct Elasticsearch RBAC scopeEPSS 0.5%CVE-2026-26935MEDIUMImproper Input Validation in Kibana Leading to Denial of ServiceEPSS 0.5%CVE-2026-26937MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of ServiceEPSS 0.5%CVE-2026-26934MEDIUMImproper Validation of Specified Quantity in Input in Kibana Leading to Denial of ServiceEPSS 0.5%