Vulnerability Description
It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, which may be intentionally hidden from public view. Using this vulnerability, a malicious user with the ability to create connectors, could utilize these connectors to view limited HTTP response data on hosts accessible to the cluster.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Elastic | Kibana | >= 7.8.0, < 7.15.2 |
Related Weaknesses (CWE)
References
- https://discuss.elastic.co/t/kibana-7-15-2-security-update/288923Vendor Advisory
- https://discuss.elastic.co/t/kibana-7-15-2-security-update/288923Vendor Advisory
FAQ
What is CVE-2021-37939?
CVE-2021-37939 is a vulnerability with a CVSS score of 2.7 (LOW). It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, which may be intentionally hidden from public view. Using this vu...
How severe is CVE-2021-37939?
CVE-2021-37939 has been rated LOW with a CVSS base score of 2.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-37939?
Check the references section above for vendor advisories and patch information. Affected products include: Elastic Kibana.