Description
Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScript in users' browsers.
Remediation
References
http://www.securityfocus.com/bid/99179
https://www.elastic.co/community/security
Related Vulnerabilities
CVE-2021-23443 Vulnerability in npm package edge.js
CVE-2023-37903 Vulnerability in npm package vm2
CVE-2020-36179 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2017-5645 Vulnerability in maven package org.apache.logging.log4j:log4j-core
CVE-2019-17579 Vulnerability in maven package org.sonarsource.sonarqube:sonar-web