Executive brief
Kibana's JIRA and IBM Resilient connectors could be exploited to return HTTP response data from internal hosts. A user with connector creation privileges could abuse this functionality to view limited HTTP response data from hosts accessible to the Elastic cluster, potentially exposing sensitive internal information.
Technical details
The vulnerability exists in Kibana's JIRA and IBM Resilient connectors, which failed to properly restrict access to HTTP response data. An authenticated attacker with the ability to create connectors (typically a high-privilege user) can craft requests through these connectors to retrieve HTTP response data from internal hosts that would normally be hidden from public view. The connector functionality did not properly validate or filter HTTP responses, allowing information disclosure. This affects versions 7.8.0 through 7.15.1; the fix was released in version 7.15.2.
Affected products
- Elastic Kibana 7.8.0 through 7.15.1
Timeline
- 2021-11-18: disclosed: CVE-2021-37939 published
- 2021-11-10: patched: Fixed in Kibana 7.15.2