CVE-2021-22150
It was discovered that a user with Fleet admin permissions could upload a malicious package. Due to using an older versi
It was discovered that a user with Fleet admin permissions could upload a malicious package. Due to using an older version of the js-yaml library, this package would be loaded in an insecure manner, allowing an attacker to execute commands on the Kibana server.
MEDIUM · CVSS 6.6
EPSS 0.00178
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0