Description
Kibana versions after 5.1.1 and before 5.6.7 and 6.1.3 had a cross-site scripting (XSS) vulnerability in the tag cloud visualization that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
Remediation
References
https://discuss.elastic.co/t/elastic-stack-6-1-3-and-5-6-7-security-update/117683
Related Vulnerabilities
CVE-2016-3093 Vulnerability in maven package org.apache.struts.xwork:xwork-core
CVE-2018-16115 Vulnerability in maven package com.typesafe.akka:akka-actor_2.11
CVE-2011-4838 Vulnerability in maven package org.jruby:jruby
CVE-2022-34804 Vulnerability in maven package org.jenkins-ci.plugins:opsgenie
CVE-2021-20328 Vulnerability in maven package org.mongodb:mongodb-driver-sync