Exposição de Kibana

JavaScript graphics, Search engines
44
score de exposição
4
sites usam
1
em exploração
8
críticos
Análise Vexday

Com 107 CVEs catalogadas, o Kibana apresenta taxa de exploração ativa 2,1 vezes acima da média geral do catálogo CISA KEV, o que indica uma superfície de ataque com histórico real de abuso, não apenas risco teórico. A CVE mais perigosa em exploração ativa é a CVE-2019-7609, com score EPSS de 0,95, sinalizando altíssima probabilidade de tentativas de exploração em ambientes expostos. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), relevante em ferramentas de visualização onde interfaces web são parte central da funcionalidade. O surgimento de 15 novas CVEs nos últimos 90 dias, combinado com 8 de severidade crítica, reforça a necessidade de manter o Kibana atualizado e com acesso devidamente restrito.

CVEs

124 resultados
CVE-2019-7609CRITICALKibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the EPSS 95.3%KEVCVE-2018-17246Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the KibanEPSS 82.3%CVE-2025-25014CRITICALKibana arbitrary code execution via prototype pollutionEPSS 21.5%CVE-2020-7012Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authenticated attacker witEPSS 18.2%CVE-2019-7610Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpaEPSS 3.9%CVE-2020-7013Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB EPSS 2.1%CVE-2019-7616Kibana versions before 6.8.2 and 7.2.1 contain a server side request forgery (SSRF) flaw in the graphite integration for Timelion visualizerEPSS 2.1%CVE-2024-23443MEDIUMA high-privileged user, allowed to create custom osquery packs 17 could affect the availability of Kibana by uploading a maliciously craftedEPSS 1.8%CVE-2024-37287CRITICALKibana arbitrary code execution via prototype pollutionEPSS 1.6%CVE-2018-3830Kibana versions 5.3.0 to 6.4.1 had a cross-site scripting (XSS) vulnerability via the source field formatter that could allow an attacker toEPSS 1.6%CVE-2018-17245Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating PEPSS 1.5%CVE-2017-8452Kibana versions prior to 5.2.1 configured for SSL client access, file descriptors will fail to be cleaned up after certain requests and willEPSS 1.4%CVE-2019-7608Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XSS) vulnerability that could allow an attacker to obtain sensitive infoEPSS 1.3%CVE-2025-25015CRITICALKibana arbitrary code execution via prototype pollutionEPSS 1.3%CVE-2024-37285CRITICALKibana arbitrary code execution via YAML deserializationEPSS 1.3%CVE-2020-7017In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or crEPSS 1.2%CVE-2021-22150MEDIUMKibana code execution issueEPSS 1.2%CVE-2020-7016Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewedEPSS 1.1%CVE-2018-3818Kibana versions 5.1.1 to 6.1.2 and 5.6.6 had a cross-site scripting (XSS) vulnerability via the colored fields formatter that could allow anEPSS 1.0%CVE-2016-10365Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link in the Kibana domaiEPSS 1.0%