Description
Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScript in users' browsers.
Remediation
References
https://www.elastic.co/community/security
http://www.securityfocus.com/bid/99179
Related Vulnerabilities
CVE-2020-1959 Vulnerability in maven package org.apache.syncope.client:syncope-client-enduser
CVE-2022-46688 Vulnerability in maven package org.jenkins-ci.plugins:sonar-gerrit
CVE-2020-35509 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2022-41252 Vulnerability in maven package org.jenkins-ci.plugins:cons3rt
CVE-2023-43495 Vulnerability in maven package org.jenkins-ci.main:jenkins-core