Beveiligingsadvies

CVE-2021-22150

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-11-22 00:30:56
Laatst bijgewerkt 2024-12-02 20:33:49
Toegewezen door elastic
CVSS-score 6.6
Status PUBLISHED

Beschrijving

It was discovered that a user with Fleet admin permissions could upload a malicious package. Due to using an older version of the js-yaml library, this package would be loaded in an insecure manner, allowing an attacker to execute commands on the Kibana server.