{"id":"CVE-2021-22142","details":"Kibana contains an embedded version of the Chromium browser that the Reporting feature uses to generate the downloadable reports. If a user with permissions to generate reports is able to render arbitrary HTML with this browser, they may be able to leverage known Chromium vulnerabilities to conduct further attacks. Kibana contains a number of protections to prevent this browser from rendering arbitrary content.","modified":"2026-04-10T04:29:57.806151Z","published":"2023-11-22T01:15:07.210Z","references":[{"type":"ADVISORY","url":"https://www.elastic.co/community/security"},{"type":"ADVISORY","url":"https://discuss.elastic.co/t/elastic-stack-7-13-0-and-6-8-16-security-update/273964/1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/kibana","events":[{"introduced":"ee89fda8a17eff9c93f7400c102edf76cb4d7d8a"},{"fixed":"9863e88bd63ad546b9d36e6b0c0c55cb65dd9081"}],"database_specific":{"versions":[{"introduced":"7.0.0"},{"fixed":"7.13.0"}]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-22142.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}