OSV 1.4.0 · unreviewed · 修改于 2021-11-24 08:01
发布时间
2021-11-19 08:00
GitHub 审查时间
—
NVD 发布时间
2021-11-19 00:15
源文件
advisories/unreviewed/2021/11/GHSA-pfm6-x9q4-rphr/GHSA-pfm6-x9q4-rphr.json
It was discovered that on Windows operating systems specifically, Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host to load internal files ending in the .pbf extension. Thanks to Dominic Couture for finding this vulnerability.
该公告没有提供结构化的受影响软件包信息。