Home
MEDIUM: 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NDefault status
unaffected
7.17.0 (semver) before 7.17.18
affected
8.0.0 (semver) before 8.13.0
affected
Description
Unrestricted file upload in Kibana allows an authenticated attacker to compromise software integrity by uploading a crafted malicious file due to insufficient server-side validation.
Problem types
CWE-434 Unrestricted Upload of File with Dangerous Type
Product status
7.17.0 (semver) before 7.17.18
8.0.0 (semver) before 8.13.0
References
discuss.elastic.co/...3-0-security-update-esa-2024-47/377711