# Kibana 4.x XSS -- CVE pending

**URL:** <https://discuss.elastic.co/t/kibana-4-x-xss-cve-pending/37523>\
**Category:** Security Announcements\
**Created:** [December 18, 2015, 12:53am UTC](https://discuss.elastic.co/t/kibana-4-x-xss-cve-pending/37523 "2015-12-18T00:53:40Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![KevinKluge](https://avatars.discourse-cdn.com/v4/letter/k/dfb087/32.png) [@KevinKluge](https://discuss.elastic.co/u/KevinKluge)\
**Post date:** [December 18, 2015, 12:53am UTC](https://discuss.elastic.co/t/kibana-4-x-xss-cve-pending/37523/1 "2015-12-18T00:53:40Z")

</div>

**Summary**  
Kibana versions up to and including 4.3.0, 4.2.1, and 4.1.3 are vulnerable to a cross-site scripting (XSS) attack. The attack allows execution of arbitrary JavaScript in the context of the user’s browser.

We have requested a CVE number and will update our forum post and website when the number has been assigned.

Thanks to Vladimir Ivanov (Positive Technologies) for finding and responsibly reporting the issue.

**Fixed Versions**  
Versions 4.3.1, 4.2.2, and 4.1.4 have addressed the vulnerability.

**Remediation**  
Users should upgrade Kibana to 4.3.1, 4.2.2, or 4.1.4. This will address the vulnerability.

[Found](https://www.elastic.co/found) customers are being updated automatically.

---

_[View the full topic](https://discuss.elastic.co/t/kibana-4-x-xss-cve-pending/37523)._
