CVE-2020-10743

Source
https://cve.org/CVERecord?id=CVE-2020-10743
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-10743.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-10743
Downstream
Related
Published
2021-06-02T11:15:07.897Z
Modified
2026-07-08T05:55:14.389409980Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercept and manipulate requests. This flaw allows an attacker to trick a user into performing arbitrary actions in OCP's distribution of Kibana, such as clickjacking.

Database specific
{
    "unresolved_ranges": [
        {
            "source": "CPE_STRING",
            "cpes": [
                "cpe:2.3:a:redhat:openshift_container_platform:3.11.286:*:*:*:*:*:*:*"
            ],
            "vendor_product": "redhat:openshift_container_platform",
            "extracted_events": [
                {
                    "introduced": "3.11.286"
                },
                {
                    "last_affected": "3.11.286"
                }
            ]
        }
    ]
}
References

Affected packages

Git / github.com/elastic/kibana

Affected ranges

Type
GIT
Repo
https://github.com/elastic/kibana
Events
Database specific
{
    "cpe": "cpe:2.3:a:redhat:openshift_container_platform:4.6.1:*:*:*:*:*:*:*",
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "4.6.1"
        },
        {
            "last_affected": "4.6.1"
        }
    ]
}

Affected versions

4.*
4.6.1
v4.*
v4.6.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-10743.json"