CyberRota Analysis
AI-GeneratedKibana is vulnerable due to a misconfiguration that allows lower-privileged users to access data they should not be authorized to view, leveraging another user's privileges. This flaw can lead to unauthorized information exposure, posing a risk to data confidentiality. Organizations using Kibana should prioritize addressing this vulnerability to safeguard sensitive information from potential leaks.
Original NVD Description
Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a lower-privileged user can cause data from sources they are not authorized to access to be processed using another user's privileges.
Related CVEs
Other vulnerabilities affecting the same vendor(s)