{"id":"CVE-2022-23711","details":"A vulnerability in Kibana could expose sensitive information related to Elastic Stack monitoring in the Kibana page source. Elastic Stack monitoring features provide a way to keep a pulse on the health and performance of your Elasticsearch cluster. Authentication with a vulnerable Kibana instance is not required to view the exposed information. The Elastic Stack monitoring exposure only impacts users that have set any of the optional monitoring.ui.elasticsearch.* settings in order to configure Kibana as a remote UI for Elastic Stack Monitoring. The same vulnerability in Kibana could expose other non-sensitive application-internal information in the page source.","modified":"2026-08-12T13:33:39.354604Z","published":"2022-04-21T18:22:58Z","database_specific":{"cwe_ids":["CWE-200"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23711.json","cna_assigner":"elastic"},"references":[{"type":"WEB","url":"https://discuss.elastic.co/t/kibana-7-17-3-and-8-1-3-security-update/302826"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23711.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23711"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/elasticsearch","events":[{"introduced":"fe6cb20130087b7dcdeb3f1b97724a73a8581176"},{"fixed":"5ad023604c8d7416c9eb6c0eadb62b14e766caff"},{"introduced":"1b6a7ece17463df5ff54a3e1302d825889aa1161"},{"fixed":"39afaa3c0fe7db4869a161985e240bd7182d7a07"}],"database_specific":{"cpe":"cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"7.2.1"},{"fixed":"7.17.3"},{"introduced":"8.0.0"},{"fixed":"8.1.3"}],"source":"CPE_RANGE"}}],"database_specific":{"vanir_signatures_modified":"2026-08-12T13:33:39Z","vanir_signatures":[{"digest":{"line_hashes":["226746288825378703638102732499045764617","51954006983763301664690218603040736561","94248876803817470752986194230926600107","181651084104348884952860661374425707726","244578646769380242508145984864431558008","43986145692724068795445323664798210238","184471658701666151651060587773609227366","117172758192052358444967644918231603911","210887714201632359315121647961272051213","337372700772356445169455986021813101477","91066003754751162947794538790145202973","109380481588660022934991737162516744180","137725886286116476570003173386035228993","338542034775493872112960430106128476353","205461146723756599659909024544001289166","121940840335845670198574631024784524218","149801921585451126494913010187150007025","26289108481650827357209955847572029729","140920743991183009064221681933238616134","26700876627240915765018257732498046144","22524171056212110336925643524124682845","231905658005736863867231550773425296872","157236737340016126840422815639928306598","128546491118816073262677523142458330440","80413917189518397984383842594274074417","336843503148321852210733394665347129318","27294374586467464996780686933872057147","285542680045861299362377448547103641829","52383003218755168632743047368620560429","238363036610979234623122646514621361026","57678399081765758610468124658958009850","325965442664591113752083567063423075905","150222159741521458993501823226742755964","176861291663358766507647826545408242176","144226727207264808098418760579132726207","310272483516737980255688731200884832466","208415228872309851195009938818255200176","62818158992565308129373979168238326214","102415316796209090643568465271241166558","177535050844847406777578286571803985642","299276906746152935264530981089462616200","40271367959698558752323828360331454842","143159085264269971750492205323019902652"],"threshold":0.9},"id":"CVE-2022-23711-2e072a95","signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/5ad023604c8d7416c9eb6c0eadb62b14e766caff","target":{"file":"x-pack/plugin/core/src/main/java/org/elasticsearch/license/LicenseOverrides.java"},"deprecated":false},{"deprecated":false,"digest":{"line_hashes":["189429231053651711928670831262595559951","120931940257222668093560937228530422520","65781372537795053822363599125604600778","321870558477757942034909763141987718446","311877206880458011756308685864844119296","11197098092488603129585258900231914908","284166842650105473715532247937864622594","233012298240354145023185006885884197302","91953934665566113267560573580178448216","195193340358054412461938044118036864487","317218021715458504821244664715907271145","155291076504012054375067459852288539872","192574208064753613626242252096865613302","52660984168845637045341640728909257164","329948673025055053407524131442133706360","67239362226479063578242391132040634817","51223689959899344995892165369735370973","157347951674530010337427385801425726916","110499132009880333792013118071924839034","135047860194879463544088693854587056003","238017376863645154729146858811745043342","336687823566145009391068011248829173877","96841945446958595341465137304834649157","289096786845545755383451269674197599070","315840073708111641595167665100486559207","15456228915226168368698097868296997784","142080015479253048393025847130956178330","168411022524018653948067047059533406029","106810097401145167736796766584850336668","276075428136253326313062717786750125590","33294834772544657739959021826849484143","179729583263336265464052651935412731469","158285436967265575219004445786598068092","5954822042271131695204775060395009626","126179912202256572544356303764086698660","84471537753004225575775402600008062384","294111509922655315538191698229786067726","267613384098008301574103542143758235858","248800874030255868940863996344326985947","203044426381860048244508567344198793326","305284114510460813871888401957676702764","20126600790631056954502879179576621005","25375559383284192657540335732180692420"],"threshold":0.9},"id":"CVE-2022-23711-a79bc640","signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/39afaa3c0fe7db4869a161985e240bd7182d7a07","target":{"file":"x-pack/plugin/core/src/main/java/org/elasticsearch/license/LicenseOverrides.java"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23711.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/kibana","events":[{"introduced":"ffd4de9b9f5a85037c2acfcaecdc566975bb6355"},{"fixed":"dcd0a101ed880bb10a4dcf511b91fd611d8c805d"},{"introduced":"57ca5e139a33dd2eed927ce98d8231a1f217cd15"},{"fixed":"c44c8c44c82ed80d1ae3dd990291dcc85b7a27dc"}],"database_specific":{"cpe":"cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"7.2.1"},{"fixed":"7.17.3"},{"introduced":"8.0.0"},{"fixed":"8.1.3"}],"source":"CPE_RANGE"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23711.json"}}],"schema_version":"1.9.0"}