Withdrawn: Cross-site Scripting in Kibana
Moderate severity
GitHub Reviewed
Published
Mar 4, 2022
to the GitHub Advisory Database
•
Updated Mar 15, 2023
Withdrawn
This advisory was withdrawn on Mar 15, 2023
Package
Affected versions
>= 7.16.0, < 7.17.1
Patched versions
7.17.1
Description
Published by the National Vulnerability Database
Mar 3, 2022
Published to the GitHub Advisory Database
Mar 4, 2022
Reviewed
Mar 19, 2022
Withdrawn
Mar 15, 2023
Last updated
Mar 15, 2023
##Withdrawn: This advisory is for Kibana, not ElasticSearch as it was originally published, and is withdrawn as being out of scope of our supported ecosystems.
A cross-site-scripting (XSS) vulnerability was discovered in the Data Preview Pane (previously known as Index Pattern Preview Pane) which could allow arbitrary JavaScript to be executed in a victim's browser.
References