BIT-elk-2026-63142

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/elk/BIT-elk-2026-63142.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-elk-2026-63142
Aliases
Published
2026-07-28T08:53:30.908Z
Modified
2026-07-28T09:56:50.111952732Z
Summary
Incomplete List of Disallowed Inputs in Kibana Leading to Server-Side Request Forgery
Details

Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.

Database specific
{
    "cpes": [
        "cpe:2.3:a:elasticsearch:kibana:*:*:*:*:*:node.js:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / elk

Package

Name
elk
Purl
pkg:bitnami/elk

Severity

  • 5.0 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
8.0.0
Fixed
8.19.19
Introduced
9.0.0
Fixed
9.3.8
Introduced
9.4.0
Fixed
9.4.4

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/elk/BIT-elk-2026-63142.json"