CyberRota Analysis
AI-GeneratedKibana's Reporting feature contains an incomplete list of disallowed inputs, enabling authenticated attackers to bypass outbound request restrictions set by administrators. This vulnerability could lead to unauthorized network requests, potentially exposing sensitive data or services that should be protected by security policies. Organizations using Kibana, especially those with reporting capabilities, should prioritize addressing this issue to mitigate potential security risks.
Original NVD Description
Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.
Related CVEs
Other vulnerabilities affecting the same vendor(s)