CyberRota Analysis
AI-GeneratedKibana is vulnerable due to a missing authorization mechanism that allows users with limited privileges to access sensitive workflow execution outputs without proper authorization. This can lead to unauthorized information disclosure, potentially exposing sensitive data from connected data sources. Organizations using Kibana should prioritize addressing this vulnerability to protect against potential data leaks and ensure compliance with data access policies.
Original NVD Description
Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workflow execution outputs in their Kibana space without the authorization required to do so through the documented API. The accessible data may include sensitive information returned by workflow steps, such as results from connected data sources that the caller would not otherwise be authorized to access.
Related CVEs
Other vulnerabilities affecting the same vendor(s)