Description
Kibana versions after 6.1.0 and before 6.1.3 had a cross-site scripting (XSS) vulnerability in labs visualizations that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
Remediation
References
https://discuss.elastic.co/t/elastic-stack-6-1-3-and-5-6-7-security-update/117683
Related Vulnerabilities
CVE-2022-29040 Vulnerability in maven package org.jenkins-ci.plugins:git-parameter
CVE-2020-6506 Vulnerability in npm package react-native-webview
CVE-2015-8862 Vulnerability in maven package org.webjars.npm:mustache
CVE-2023-44794 Vulnerability in maven package cn.dev33:sa-token-core
CVE-2023-31101 Vulnerability in maven package org.apache.inlong:manager-service