Total vulnerabilities in the database
It was discovered that Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host to load internal files ending in the .pbf extension.
Software | From | Fixed in |
---|---|---|
elastic / kibana | 7.9.0 | 7.14.0.x |