BIT-kibana-2026-63142

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/kibana/BIT-kibana-2026-63142.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-kibana-2026-63142
Aliases
Published
2026-07-28T08:58:14Z
Modified
2026-09-08T08:48:23Z
Summary
Incomplete List of Disallowed Inputs in Kibana Leading to Server-Side Request Forgery
Details

Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.

Database specific
{
    "cpes":  [
        "cpe:2.3:a:elasticsearch:kibana:*:*:*:*:*:node.js:*:*"
    ],
    "severity":  "Medium"
}
References

Affected packages

Bitnami / kibana

Package

Name
kibana
Purl
pkg:bitnami/kibana

Severity

  • 5.0 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
8.0.0
Fixed
8.19.19
Introduced
9.0.0
Fixed
9.3.8
Introduced
9.4.0
Fixed
9.4.4

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/kibana/BIT-kibana-2026-63142.json"