Beveiligingsadvies

CVE-2021-22151

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-11-22 00:36:51
Laatst bijgewerkt 2024-10-11 18:06:45
Toegewezen door elastic
CVSS-score 3.1
Status PUBLISHED

Beschrijving

It was discovered that Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host to load internal files ending in the .pbf extension.