Security Advisory

CVE-2021-22151

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-11-22 00:36:51
Last updated 2024-10-11 18:06:45
Assigner elastic
State PUBLISHED

Description

It was discovered that Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host to load internal files ending in the .pbf extension.