Description
It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, which may be intentionally hidden from public view.
Recommendation
Update the kibana package to the latest compatible version. Followings are version details:
- Affected version(s): >= 7.8.0, <= 7.15.1
- Patched version(s): 7.15.2
References
Could your website be exposed too?
SmartScanner can check your website for Kibana Sensitive Data Disclosure and gives you actionable findings to investigate.
Start a free scanRelated Issues
- The AuthKit React Router Library rendered sensitive auth data in HTML - CVE-2025-55008
- Sensitive data exposure in NATS - CVE-2020-26149
- Prototype Pollution in js-data - js-data - CVE-2021-23574
- Sensitive data exposure in NATS - nats - CVE-2020-26149
You might also like:
See something that needs correcting? Let us knowUpdated July 11, 2023


