QID 379177
Date Published: 2024-01-25
QID 379177: Elasticsearch Kibana Storage of Sensitive Information into Log File (ESA-2023-25)
Kibana is a source-available data visualization dashboard software for Elasticsearch.
CVE-2023-46671: The error message recorded in the log may contain account credentials for the kibana_system user, API Keys, and credentials of Kibana end-users.
Affected Version:
Kibana versions from 8.0.0 to 8.11.0.
QID Detection Logic (Authenticated):
This authenticated QID checks for Kibana version by running "kibana --version" command.
QID Detection Logic (Unauthenticated):
This QID sends a GET request to find if the target is running a vulnerable version of kibana.
Successful exploitation of these vulnerabilities may affect confidentiality, integrity and availability of the targeted user.
Solution
Update to version 8.11.1. Kibana can be downloaded at Download Kibana 8.11.1
Vendor References
CVEs related to QID 379177
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ESA-2023-25 |
|