{"id":"CVE-2019-7608","details":"Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XSS) vulnerability that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.","modified":"2026-07-08T16:08:30.972445Z","published":"2019-03-25T19:29:02.100Z","references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHBA-2019:2824"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:2860"},{"type":"ADVISORY","url":"https://discuss.elastic.co/t/elastic-stack-6-6-1-and-5-6-15-security-update/169077"},{"type":"ADVISORY","url":"https://www.elastic.co/community/security"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/elasticsearch","events":[{"introduced":"0"},{"fixed":"fe7575a32e23e15e0a77677dc1a180206554228b"},{"introduced":"8f0685b924b9159807704ec2593b26e28105da44"},{"fixed":"1fd8f691bf2e467057b864eea9103a6e3345af3e"}],"database_specific":{"cpe":"cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"5.6.15"},{"introduced":"6.0.0"},{"fixed":"6.6.1"}],"source":"CPE_RANGE"}}],"versions":["v6.6.0","v5.6.14","v5.6.13","v5.6.12","v5.6.11","v5.6.10","v5.6.9","v5.6.8","v5.6.7","v5.6.6","v5.6.5","v5.6.4","v5.6.3","v5.6.2","v5.6.1","v5.6.0","v6.0.0-alpha2","v6.0.0-alpha1","v5.0.0-alpha5","v1.0.0.RC1","v1.0.0.Beta2","v1.0.0.Beta1","v0.90.0","v0.90.0.RC2","v0.90.0.RC1","v0.90.0.Beta1","v0.20.0.RC1","v0.19.0","v0.19.0.RC3","v0.19.0.RC2","v0.19.0.RC1","v0.18.0","v0.17.0","v0.16.0","v0.15.0","v0.14.0","v0.13.0","v0.12.0","v0.11.0","v0.10.0","v0.9.0","v0.8.0","v0.7.1","v0.7.0","v0.6.0","v0.5.1","v0.5.0","v0.4.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-7608.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/kibana","events":[{"introduced":"0"},{"fixed":"e4f1e8f824c4cdc70bfa09a5ec734d7108366456"},{"introduced":"f8bc449f5a6b28d0597730b1cf03fefe7e33422e"},{"fixed":"c0c81857d435f499ec2514d9a4823e3dc87021bd"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"5.6.15"},{"introduced":"6.0.0"},{"fixed":"6.6.1"}]}}],"versions":["v6.6.0","v5.6.14","v5.6.13","v5.6.12","v5.6.11","v5.6.10","v5.6.8","v5.6.7","v5.6.6","v5.6.5","v5.6.4","v5.6.3","v5.6.2","v5.6.1","v5.6.0","v6.0.0-alpha2","v6.0.0-alpha1","v5.0.0-alpha5","v4.2.0-beta1","v4.0.0-beta3","v4.0.0-beta2","v4.0.0-beta1.1","v4.0.0-beta1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-7608.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}