Elastic App Search versions before 7.7.0 contain a cross site scripting (XSS) flaw when displaying document URLs in the Reference UI. If the Reference UI injects a URL into a result, that URL will be rendered by the web browser. If an attacker is able to control the contents of such a field, they could execute arbitrary JavaScript in the victim�s web browser.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NElastic App Search
APPElastic< 7.7.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
XSS
Powiązane podatności
CVE-2021-22140HIGH7.5ten sam produkt
Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE...
CVE-2019-7609CRITICAL10.0⚠ KEVPL ✓ten sam vendor
RCE w Kibana Timelion — wykonanie kodu z uprawnieniami procesu
CVE-2015-1427CRITICAL9.8⚠ KEVPL ✓ten sam vendor
Elasticsearch: ucieczka z sandboksa Groovy i zdalne wykonanie poleceń
CVE-2025-37729CRITICAL9.1PL ✓ten sam vendor
Elastic Cloud Enterprise — Server-Side Template Injection (SSTI) w silniku Jinjava
CVE-2025-25014CRITICAL9.1PL ✓ten sam vendor
Prototype Pollution w Kibana prowadzące do RCE przez HTTP