Description
Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
Remediation
References
https://discuss.elastic.co/t/elastic-stack-5-4-1-and-5-3-3-security-updates/87952
https://www.elastic.co/blog/kibana-5-4-1-and-5-3-3-released
https://www.elastic.co/community/security
Related Vulnerabilities
CVE-2021-20334 Vulnerability in npm package mongodb-js-metrics
CVE-2023-49798 Vulnerability in npm package @openzeppelin/contracts
CVE-2016-8609 Vulnerability in maven package org.keycloak:keycloak-core
CVE-2023-32314 Vulnerability in maven package org.webjars.npm:vm2
CVE-2020-13942 Vulnerability in maven package org.apache.unomi:unomi-common