CVE-2022-23711

Source
https://cve.org/CVERecord?id=CVE-2022-23711
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23711.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-23711
Published
2022-04-21T18:22:58Z
Modified
2026-07-22T02:51:11.934195Z
Summary
[none]
Details

A vulnerability in Kibana could expose sensitive information related to Elastic Stack monitoring in the Kibana page source. Elastic Stack monitoring features provide a way to keep a pulse on the health and performance of your Elasticsearch cluster. Authentication with a vulnerable Kibana instance is not required to view the exposed information. The Elastic Stack monitoring exposure only impacts users that have set any of the optional monitoring.ui.elasticsearch.* settings in order to configure Kibana as a remote UI for Elastic Stack Monitoring. The same vulnerability in Kibana could expose other non-sensitive application-internal information in the page source.

Database specific
{
    "cwe_ids": [
        "CWE-200"
    ],
    "cna_assigner": "elastic",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23711.json"
}
References

Affected packages

Git / github.com/elastic/elasticsearch

Affected ranges

Type
GIT
Repo
https://github.com/elastic/elasticsearch
Events
Database specific
{
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "7.2.1"
        },
        {
            "fixed": "7.17.3"
        },
        {
            "introduced": "8.0.0"
        },
        {
            "fixed": "8.1.3"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23711.json"
vanir_signatures
[
    {
        "source": "https://github.com/elastic/elasticsearch/commit/5ad023604c8d7416c9eb6c0eadb62b14e766caff",
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "226746288825378703638102732499045764617",
                "51954006983763301664690218603040736561",
                "94248876803817470752986194230926600107",
                "181651084104348884952860661374425707726",
                "244578646769380242508145984864431558008",
                "43986145692724068795445323664798210238",
                "184471658701666151651060587773609227366",
                "117172758192052358444967644918231603911",
                "210887714201632359315121647961272051213",
                "337372700772356445169455986021813101477",
                "91066003754751162947794538790145202973",
                "109380481588660022934991737162516744180",
                "137725886286116476570003173386035228993",
                "338542034775493872112960430106128476353",
                "205461146723756599659909024544001289166",
                "121940840335845670198574631024784524218",
                "149801921585451126494913010187150007025",
                "26289108481650827357209955847572029729",
                "140920743991183009064221681933238616134",
                "26700876627240915765018257732498046144",
                "22524171056212110336925643524124682845",
                "231905658005736863867231550773425296872",
                "157236737340016126840422815639928306598",
                "128546491118816073262677523142458330440",
                "80413917189518397984383842594274074417",
                "336843503148321852210733394665347129318",
                "27294374586467464996780686933872057147",
                "285542680045861299362377448547103641829",
                "52383003218755168632743047368620560429",
                "238363036610979234623122646514621361026",
                "57678399081765758610468124658958009850",
                "325965442664591113752083567063423075905",
                "150222159741521458993501823226742755964",
                "176861291663358766507647826545408242176",
                "144226727207264808098418760579132726207",
                "310272483516737980255688731200884832466",
                "208415228872309851195009938818255200176",
                "62818158992565308129373979168238326214",
                "102415316796209090643568465271241166558",
                "177535050844847406777578286571803985642",
                "299276906746152935264530981089462616200",
                "40271367959698558752323828360331454842",
                "143159085264269971750492205323019902652"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2022-23711-2e072a95",
        "target": {
            "file": "x-pack/plugin/core/src/main/java/org/elasticsearch/license/LicenseOverrides.java"
        },
        "deprecated": false
    },
    {
        "source": "https://github.com/elastic/elasticsearch/commit/39afaa3c0fe7db4869a161985e240bd7182d7a07",
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "189429231053651711928670831262595559951",
                "120931940257222668093560937228530422520",
                "65781372537795053822363599125604600778",
                "321870558477757942034909763141987718446",
                "311877206880458011756308685864844119296",
                "11197098092488603129585258900231914908",
                "284166842650105473715532247937864622594",
                "233012298240354145023185006885884197302",
                "91953934665566113267560573580178448216",
                "195193340358054412461938044118036864487",
                "317218021715458504821244664715907271145",
                "155291076504012054375067459852288539872",
                "192574208064753613626242252096865613302",
                "52660984168845637045341640728909257164",
                "329948673025055053407524131442133706360",
                "67239362226479063578242391132040634817",
                "51223689959899344995892165369735370973",
                "157347951674530010337427385801425726916",
                "110499132009880333792013118071924839034",
                "135047860194879463544088693854587056003",
                "238017376863645154729146858811745043342",
                "336687823566145009391068011248829173877",
                "96841945446958595341465137304834649157",
                "289096786845545755383451269674197599070",
                "315840073708111641595167665100486559207",
                "15456228915226168368698097868296997784",
                "142080015479253048393025847130956178330",
                "168411022524018653948067047059533406029",
                "106810097401145167736796766584850336668",
                "276075428136253326313062717786750125590",
                "33294834772544657739959021826849484143",
                "179729583263336265464052651935412731469",
                "158285436967265575219004445786598068092",
                "5954822042271131695204775060395009626",
                "126179912202256572544356303764086698660",
                "84471537753004225575775402600008062384",
                "294111509922655315538191698229786067726",
                "267613384098008301574103542143758235858",
                "248800874030255868940863996344326985947",
                "203044426381860048244508567344198793326",
                "305284114510460813871888401957676702764",
                "20126600790631056954502879179576621005",
                "25375559383284192657540335732180692420"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2022-23711-a79bc640",
        "target": {
            "file": "x-pack/plugin/core/src/main/java/org/elasticsearch/license/LicenseOverrides.java"
        },
        "deprecated": false
    }
]
vanir_signatures_modified
"2026-07-22T02:51:11Z"

Git / github.com/elastic/kibana

Affected ranges

Type
GIT
Repo
https://github.com/elastic/kibana
Events
Database specific
{
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "7.2.1"
        },
        {
            "fixed": "7.17.3"
        },
        {
            "introduced": "8.0.0"
        },
        {
            "fixed": "8.1.3"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23711.json"