What the vulnerability does

01Description

It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, which may be intentionally hidden from public view. Using this vulnerability, a malicious user with the ability to create connectors, could utilize these connectors to view limited HTTP response data on hosts accessible to the cluster.

Key dates

02Disclosure timeline

November 18, 2021 CVE published
August 4, 2024 Record updated

Related vulnerabilities

04Related CVE