CVE-2022-23707

Source
https://cve.org/CVERecord?id=CVE-2022-23707
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23707.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-23707
Published
2022-02-11T17:40:27Z
Modified
2026-08-12T03:51:11.290142313Z
Summary
[none]
Details

An XSS vulnerability was found in Kibana index patterns. Using this vulnerability, an authenticated user with permissions to create index patterns can inject malicious javascript into the index pattern which could execute against other users

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23707.json",
    "cna_assigner": "elastic",
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Git / github.com/elastic/elasticsearch

Affected ranges

Type
GIT
Repo
https://github.com/elastic/elasticsearch
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "7.5.1"
        },
        {
            "fixed": "7.17.0"
        }
    ],
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23707.json"

Git / github.com/elastic/kibana

Affected ranges

Type
GIT
Repo
https://github.com/elastic/kibana
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "7.5.1"
        },
        {
            "fixed": "7.17.0"
        }
    ],
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23707.json"