{"id":"GHSA-m6gg-86c6-gfr9","summary":"Withdrawn: Cross-site Scripting in Kibana","details":"##Withdrawn: This advisory is for Kibana, not ElasticSearch as it was originally published, and is withdrawn as being out of scope of our supported ecosystems.\n\nA cross-site-scripting (XSS) vulnerability was discovered in the Data Preview Pane (previously known as Index Pattern Preview Pane) which could allow arbitrary JavaScript to be executed in a victim's browser.","aliases":["CVE-2022-23710"],"modified":"2026-09-10T03:49:17.639438524Z","published":"2022-03-04T00:00:15Z","withdrawn":"2023-03-15T19:19:13Z","database_specific":{"nvd_published_at":"2022-03-03T22:15:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-03-19T00:15:26Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23710"},{"type":"WEB","url":"https://discuss.elastic.co/t/elastic-stack-7-17-1-security-update/298447"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20220325-0009"}],"affected":[{"package":{"name":"org.elasticsearch:elasticsearch","ecosystem":"Maven","purl":"pkg:maven/org.elasticsearch/elasticsearch"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.16.0"},{"fixed":"7.17.1"}]}],"versions":["7.16.0","7.16.1","7.16.2","7.16.3","7.17.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-m6gg-86c6-gfr9/GHSA-m6gg-86c6-gfr9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}