CVE-2019-7621 (NVD)

2019-12-18

Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with the ability to create coordinate map visualizations could create a malicious visualization. If another Kibana user views that visualization or a dashboard containing the visualization it could execute JavaScript in the victim�s browser.

Products Kibana
Type Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE-79)
First patch - None (likely due to unavailable code)
Links https://discuss.elastic.co/t/elastic-stack-6-8-6-and-7-5-1-security-update/212390
https://www.elastic.co/community/security/