It was discovered that Kibana was not validating a user...
Low severity
Unreviewed
Published
Nov 22, 2023
to the GitHub Advisory Database
•
Updated Nov 22, 2023
Description
Published by the National Vulnerability Database
Nov 22, 2023
Published to the GitHub Advisory Database
Nov 22, 2023
Last updated
Nov 22, 2023
It was discovered that Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host to load internal files ending in the .pbf extension.
References