CVE-2021-22151

Publication date

2023-11-22 00:36:51

Family

elastic

State

PUBLISHED

Description

It was discovered that Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host to load internal files ending in the .pbf extension.