Kibana Unrestricted Upload of File with Dangerous Type Can Lead to XSS
Vulnerability Description
Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s browser (XSS) via crafted HTML and JavaScript files. The attacker must have access to the Synthetics app AND/OR have access to write to the synthetics indices.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-11390
Credits & Attribution
No credits recorded in the NVD database.
References
More from Elastic
View All →Affected Vendor
Elastic
View all reports →