CVE-2021-22150

Publication date

2023-11-22 00:30:56

Family

elastic

State

PUBLISHED

Description

It was discovered that a user with Fleet admin permissions could upload a malicious package. Due to using an older version of the js-yaml library, this package would be loaded in an insecure manner, allowing an attacker to execute commands on the Kibana server.