Информационная безопасность
[RU] switch to English


Дополнительная информация

  Cводка уязвимостей безопасности в Web-приложениях (PHP, ASP, JSP, CGI, Perl)

  XSS vulnerability Adobe Connect 9.3 (CVE-2015-0343 )

  [SYSS-2015-020] ZENWorks Mobile Management - Cross-Site Scripting

  ZCMS SQL Injection & Persistent XSS

  Nakid-CMS CSRF, Persistent XSS & LFI

From:ELASTIC
Date:14 июня 2015 г.
Subject:Kibana vulnerability CVE-2015-4093



Summary:
Kibana versions 4.0.0, 4.0.1 and 4.0.2 are vulnerable to a cross-site scripting (XSS) attack.  The attack allows execution of arbitrary JavaScript in the context of the user’s browser.

We have been assigned CVE-2015-4093 for this issue.


Fixed versions:
Versions  4.0.3 and 4.1.0 have addressed the vulnerability.


Remediation:
Users running with Kibana 4.0.0-4.0.2 should upgrade to 4.0.3. This will address the vulnerability.


CVSS
Overall CVSS score: 5.4

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород