Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:32218
HistoryJun 14, 2015 - 12:00 a.m.

Kibana vulnerability CVE-2015-4093

2015-06-1400:00:00
vulners.com
36

Summary:
Kibana versions 4.0.0, 4.0.1 and 4.0.2 are vulnerable to a cross-site scripting (XSS) attack. The attack allows execution of arbitrary JavaScript in the context of the user’s browser.

We have been assigned CVE-2015-4093 for this issue.

Fixed versions:
Versions 4.0.3 and 4.1.0 have addressed the vulnerability.

Remediation:
Users running with Kibana 4.0.0-4.0.2 should upgrade to 4.0.3. This will address the vulnerability.

CVSS
Overall CVSS score: 5.4

Related for SECURITYVULNS:DOC:32218