Description
Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
Remediation
References
https://www.elastic.co/community/security
https://www.elastic.co/blog/kibana-5-4-1-and-5-3-3-released
https://discuss.elastic.co/t/elastic-stack-5-4-1-and-5-3-3-security-updates/87952
Related Vulnerabilities
CVE-2020-2256 Vulnerability in maven package org.jenkins-ci.plugins:pipeline-maven-parent
CVE-2022-22932 Vulnerability in maven package org.apache.karaf:apache-karaf
CVE-2022-47551 Vulnerability in maven package io.apiman:apiman-common-config
CVE-2020-1694 Vulnerability in npm package keycloak-connect
CVE-2019-10382 Vulnerability in maven package org.jenkins-ci.plugins:labmanager