CVE-2021-37936
Last modified
CVE-2021-37936 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. It was discovered that Kibana was not sanitizing document fields containing HTML snippets. Using this vulnerability, an attacker with the ability to write documents to an elasticsearch index could inject HTML. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
It was discovered that Kibana was not sanitizing document fields containing HTML snippets. Using this vulnerability, an attacker with the ability to write documents to an elasticsearch index could inject HTML. When the Discover app highlighted a search term containing the HTML, it would be rendered for the user.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Elastic | Kibana | < 7.14.1 |
References
- https://discuss.elastic.co/t/elastic-stack-7-14-1-security-update/283077Mitigation, Vendor Advisory
- https://www.elastic.co/community/security/Mitigation, Vendor Advisory
- https://discuss.elastic.co/t/elastic-stack-7-14-1-security-update/283077Mitigation, Vendor Advisory
- https://www.elastic.co/community/security/Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-37936?
How severe is CVE-2021-37936?
How do I fix CVE-2021-37936?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-3793An improper access control vulnerability was reported in som…5.3
- CVE-2021-37930Zoho ManageEngine ADManager Plus version 7110 and prior allo…9.8
- CVE-2021-37931Zoho ManageEngine ADManager Plus version 7110 and prior allo…9.8
- CVE-2021-37933An LDAP injection vulnerability in /account/login in Huntflo…7.5
- CVE-2021-37934Due to insufficient server-side login-attempt limit enforcem…9.8
- CVE-2021-37935An information disclosure vulnerability in the login page of…7.5
- CVE-2021-37937An issue was found with how API keys are created with the Fl…8.8
- CVE-2021-37938It was discovered that on Windows operating systems specific…4.3
- CVE-2021-37939It was discovered that Kibana’s JIRA connector & IBM Resilie…2.7
- CVE-2021-3794vuelidate is vulnerable to Inefficient Regular Expression Co…7.5
- CVE-2021-37940An information disclosure via GET request server-side reques…6.8
- CVE-2021-37941A local privilege escalation issue was found with the APM Ja…7.8
Are you affected by CVE-2021-37936?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
