A vulnerability in Kibana could expose sensitive information related to Elastic Stack monitoring in the Kibana page source. Elastic Stack monitoring features provide a way to keep a pulse on the health and performance of your Elasticsearch cluster. Authentication with a vulnerable Kibana instance is not required to view the exposed information. The Elastic Stack monitoring exposure only impacts users that have set any of the optional monitoring.ui.elasticsearch.* settings in order to configure Kibana as a remote UI for Elastic Stack Monitoring. The same vulnerability in Kibana could expose other non-sensitive application-internal information in the page source.
{
"cwe_ids": [
"CWE-200"
],
"cna_assigner": "elastic",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23711.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23711.json"
[
{
"source": "https://github.com/elastic/elasticsearch/commit/5ad023604c8d7416c9eb6c0eadb62b14e766caff",
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"line_hashes": [
"226746288825378703638102732499045764617",
"51954006983763301664690218603040736561",
"94248876803817470752986194230926600107",
"181651084104348884952860661374425707726",
"244578646769380242508145984864431558008",
"43986145692724068795445323664798210238",
"184471658701666151651060587773609227366",
"117172758192052358444967644918231603911",
"210887714201632359315121647961272051213",
"337372700772356445169455986021813101477",
"91066003754751162947794538790145202973",
"109380481588660022934991737162516744180",
"137725886286116476570003173386035228993",
"338542034775493872112960430106128476353",
"205461146723756599659909024544001289166",
"121940840335845670198574631024784524218",
"149801921585451126494913010187150007025",
"26289108481650827357209955847572029729",
"140920743991183009064221681933238616134",
"26700876627240915765018257732498046144",
"22524171056212110336925643524124682845",
"231905658005736863867231550773425296872",
"157236737340016126840422815639928306598",
"128546491118816073262677523142458330440",
"80413917189518397984383842594274074417",
"336843503148321852210733394665347129318",
"27294374586467464996780686933872057147",
"285542680045861299362377448547103641829",
"52383003218755168632743047368620560429",
"238363036610979234623122646514621361026",
"57678399081765758610468124658958009850",
"325965442664591113752083567063423075905",
"150222159741521458993501823226742755964",
"176861291663358766507647826545408242176",
"144226727207264808098418760579132726207",
"310272483516737980255688731200884832466",
"208415228872309851195009938818255200176",
"62818158992565308129373979168238326214",
"102415316796209090643568465271241166558",
"177535050844847406777578286571803985642",
"299276906746152935264530981089462616200",
"40271367959698558752323828360331454842",
"143159085264269971750492205323019902652"
],
"threshold": 0.9
},
"id": "CVE-2022-23711-2e072a95",
"target": {
"file": "x-pack/plugin/core/src/main/java/org/elasticsearch/license/LicenseOverrides.java"
},
"deprecated": false
},
{
"source": "https://github.com/elastic/elasticsearch/commit/39afaa3c0fe7db4869a161985e240bd7182d7a07",
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"line_hashes": [
"189429231053651711928670831262595559951",
"120931940257222668093560937228530422520",
"65781372537795053822363599125604600778",
"321870558477757942034909763141987718446",
"311877206880458011756308685864844119296",
"11197098092488603129585258900231914908",
"284166842650105473715532247937864622594",
"233012298240354145023185006885884197302",
"91953934665566113267560573580178448216",
"195193340358054412461938044118036864487",
"317218021715458504821244664715907271145",
"155291076504012054375067459852288539872",
"192574208064753613626242252096865613302",
"52660984168845637045341640728909257164",
"329948673025055053407524131442133706360",
"67239362226479063578242391132040634817",
"51223689959899344995892165369735370973",
"157347951674530010337427385801425726916",
"110499132009880333792013118071924839034",
"135047860194879463544088693854587056003",
"238017376863645154729146858811745043342",
"336687823566145009391068011248829173877",
"96841945446958595341465137304834649157",
"289096786845545755383451269674197599070",
"315840073708111641595167665100486559207",
"15456228915226168368698097868296997784",
"142080015479253048393025847130956178330",
"168411022524018653948067047059533406029",
"106810097401145167736796766584850336668",
"276075428136253326313062717786750125590",
"33294834772544657739959021826849484143",
"179729583263336265464052651935412731469",
"158285436967265575219004445786598068092",
"5954822042271131695204775060395009626",
"126179912202256572544356303764086698660",
"84471537753004225575775402600008062384",
"294111509922655315538191698229786067726",
"267613384098008301574103542143758235858",
"248800874030255868940863996344326985947",
"203044426381860048244508567344198793326",
"305284114510460813871888401957676702764",
"20126600790631056954502879179576621005",
"25375559383284192657540335732180692420"
],
"threshold": 0.9
},
"id": "CVE-2022-23711-a79bc640",
"target": {
"file": "x-pack/plugin/core/src/main/java/org/elasticsearch/license/LicenseOverrides.java"
},
"deprecated": false
}
]
"2026-07-22T02:51:11Z"