CVE-2021-37939
Kibana Sensitive Data Disclosure
EPSS 0.11%
Description
It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, which may be intentionally hidden from public view. Using this vulnerability, a malicious user with the ability to create connectors, could utilize these connectors to view limited HTTP response data on hosts accessible to the cluster.
How to fix CVE-2021-37939
To remediate CVE-2021-37939, upgrade the affected package to a fixed version below.
- npm/kibana—upgrade to 7.15.2 or later
Is CVE-2021-37939 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 7.8.0, < 7.15.2