QID 379179
Date Published: 2024-01-25
QID 379179: Elasticsearch Kibana Storage of Sensitive Information into Log File (ESA-2023-27)
Kibana is a source-available data visualization dashboard software for Elasticsearch.
CVE-2023-46675: The messages recorded in the log may contain Account credentials for the kibana_system user, API Keys, and credentials of Kibana end-users, Elastic Security package policy objects which can contain private keys, bearer token, and sessions of 3rd-party integrations and finally Authorization headers, client secrets, local file paths, and stack traces.
Affected Version:
Kibana versions from 7.13.0 to 7.17.15.
Kibana versions from 8.0.0 to 8.11.1.
QID Detection Logic (Authenticated):
This authenticated QID checks for Kibana version by running "kibana --version" command.
QID Detection Logic (Unauthenticated):
This QID sends a GET request to find if the target is running a vulnerable version of kibana.
Successful exploitation of these vulnerabilities may affect confidentiality, integrity and availability of the targeted user.
CVEs related to QID 379179
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ESA-2023-27 |
|