← back
CVE-2021-22142mediumCWE-1104

Kibana Reporting vulnerabilities

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.6epss 1.0%
exploitation probability
1.0%top 40% of all CVEs
observed exploitation
nono source reports it
In short

Kibana's reporting feature uses an embedded Chromium browser to generate downloadable reports. If a user with report generation permissions can make this browser display malicious HTML, they could exploit known Chromium vulnerabilities to attack the system.

Technical detail

The vulnerability exists in Kibana's Reporting feature, which embeds Chromium for PDF/image generation. An authenticated attacker with report generation permissions can bypass HTML rendering protections to inject arbitrary content, potentially triggering known Chromium CVEs for privilege escalation or code execution on the Kibana server.

Summary generated and translated by AI from the official description.
Kibana contains an embedded version of the Chromium browser that the Reporting feature uses to generate the downloadable reports. If a user with permissions to generate reports is able to render arbitrary HTML with this browser, they may be able to leverage known Chromium vulnerabilities to conduct further attacks. Kibana contains a number of protections to prevent this browser from rendering arbitrary content.
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
Elastic · Kibana