Description
Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
Remediation
References
https://discuss.elastic.co/t/elastic-stack-5-4-1-and-5-3-3-security-updates/87952
https://www.elastic.co/blog/kibana-5-4-1-and-5-3-3-released
https://www.elastic.co/community/security
Related Vulnerabilities
CVE-2021-32804 Vulnerability in npm package tar
CVE-2023-26473 Vulnerability in maven package org.xwiki.platform:xwiki-platform-query-manager
CVE-2023-24998 Vulnerability in maven package org.apache.tomcat:tomcat-util
CVE-2023-3315 Vulnerability in maven package org.jenkins-ci.plugins:teamconcert
CVE-2022-29037 Vulnerability in maven package org.jenkins-ci.plugins:cvs