Description
It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, which may be intentionally hidden from public view.
Recommendation
Update the kibana package to the latest compatible version. Followings are version details:
- Affected version(s): >= 7.8.0, <= 7.15.1
- Patched version(s): 7.15.2
References
Related Issues
- The AuthKit React Router Library rendered sensitive auth data in HTML - CVE-2025-55008
- Sensitive data exposure in NATS - CVE-2020-26149
- Prototype Pollution in js-data - js-data - CVE-2021-23574
- Sensitive data exposure in NATS - nats - CVE-2020-26149
You might also like:
- Tags:
- npm
- kibana
Anything's wrong? Let us know Last updated on July 11, 2023


