Description
Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScript in users' browsers.
Remediation
References
http://www.securityfocus.com/bid/99179
https://www.elastic.co/community/security
Related Vulnerabilities
CVE-2019-10760 Vulnerability in maven package org.webjars.npm:safer-eval
CVE-2022-25883 Vulnerability in npm package semver
CVE-2015-7940 Vulnerability in maven package org.bouncycastle:bcprov-jdk15on
CVE-2020-7717 Vulnerability in npm package dot-notes
CVE-2018-5653 Vulnerability in maven package org.apache.cayenne.modeler:cayenne-modeler