Vulnerability Description
It was discovered that on Windows operating systems specifically, Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host to load internal files ending in the .pbf extension. Thanks to Dominic Couture for finding this vulnerability.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Elastic | Kibana | >= 7.9.0, < 7.15.2 |
Related Weaknesses (CWE)
References
- https://discuss.elastic.co/t/kibana-7-15-2-security-update/288923Release NotesVendor Advisory
- https://discuss.elastic.co/t/kibana-7-15-2-security-update/288923Release NotesVendor Advisory
FAQ
What is CVE-2021-37938?
CVE-2021-37938 is a vulnerability with a CVSS score of 4.3 (MEDIUM). It was discovered that on Windows operating systems specifically, Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily trave...
How severe is CVE-2021-37938?
CVE-2021-37938 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-37938?
Check the references section above for vendor advisories and patch information. Affected products include: Elastic Kibana.