CyberRota Analysis
AI-GeneratedKibana is vulnerable to NoSQL Injection due to improper handling of special elements in data query logic, allowing authenticated users to manipulate queries and access unauthorized data. This could lead to significant information disclosure risks, particularly in environments where sensitive data is managed. Organizations utilizing Kibana should prioritize remediation to safeguard against potential data breaches and ensure compliance with data protection standards.
Original NVD Description
Improper Neutralization of Special Elements in Data Query Logic (CWE-943) in Kibana can lead to information disclosure via NoSQL Injection (CAPEC-676). An authenticated user with access to the affected query functionality could submit specially crafted input that alters the intended query logic, returning data the user is not authorized to read.
Related CVEs
Other vulnerabilities affecting the same vendor(s)