CVE-2022-38778 in Elastic and Decode Uri Componentproject Products
Published on February 8, 2023
A flaw (CVE-2022-38900) was discovered in one of Kibanas third party dependencies, that could allow an authenticated user to perform a request that crashes the Kibana server process.
Vulnerability Analysis
CVE-2022-38778 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. It has an exploitability score of 2.8 out of four. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Products Associated with CVE-2022-38778
You can be notified by stack.watch whenever vulnerabilities like CVE-2022-38778 are published in these products:
What versions are vulnerable to CVE-2022-38778?
- Elastic Kibana Version 8.0.0 Fixed in Version 8.6.1
- Elastic Kibana Version 7.0.0 Fixed in Version 7.17.9
- Decode Uri Componentproject Decode Uri Component Fixed in Version 0.2.1 node.js