Sploitus

CVE-2023-46671

No indexed exploits for CVE-2023-46671 yet

An issue was discovered by Elastic whereby sensitive information may be recorded in Kibana logs in the event of an error. Elastic has released Kibana 8.11.1 which resolves this issue. The error message recorded in the log may contain account credentials for the kibana_system user, API Keys, and credentials of Kibana end-users. The issue occurs infrequently, only if an error is returned from an Elasticsearch cluster, in cases where there is user interaction and an unhealthy cluster (for example, when returning circuit breaker or no shard exceptions).

Affected products
Kibana
Elastic Kibana
< 8.11.1
Fix
Available
CVSS 3.1
8.0 HIGH
EPSS
0.7% (48th percentile)
Weakness
CWE-532
NVD status
Modified
Published
2023-12-13
CVE-2023-46671 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2023-46671 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2023-46671 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.