Description
Elastic App Search versions before 7.7.0 contain a cross site scripting (XSS) flaw when displaying document URLs in the Reference UI. If the Reference UI injects a URL into a result, that URL will be rendered by the web browser. If an attacker is able to control the contents of such a field, they could execute arbitrary JavaScript in the victim�s web browser.
Remediation
References
https://www.elastic.co/community/security/
Related Vulnerabilities
CVE-2020-4070 Vulnerability in maven package org.w3c.css:css-validator
CVE-2018-14042 Vulnerability in maven package org.webjars.bowergithub.angular-ui:bootstrap
CVE-2022-34811 Vulnerability in maven package org.jenkins-ci.plugins:xpath-config-viewer
CVE-2023-2850 Vulnerability in npm package nodebb
CVE-2023-46242 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore