# Need info regarding Kibana cross site scripting (XSS) issue (ESA-2018-14)

**URL:** <https://discuss.elastic.co/t/need-info-regarding-kibana-cross-site-scripting-xss-issue-esa-2018-14/164211>\
**Category:** Kibana\
**Created:** [January 15, 2019, 12:06am UTC](https://discuss.elastic.co/t/need-info-regarding-kibana-cross-site-scripting-xss-issue-esa-2018-14/164211 "2019-01-15T00:06:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![fragatina](https://avatars.discourse-cdn.com/v4/letter/f/ccd318/32.png) [@fragatina](https://discuss.elastic.co/u/fragatina)\
**Post date:** [January 15, 2019, 12:06am UTC](https://discuss.elastic.co/t/need-info-regarding-kibana-cross-site-scripting-xss-issue-esa-2018-14/164211/1 "2019-01-15T00:06:48Z")

</div>

Hi,

currently I'm evaluating 6.x version for getting the fix regarding this:

> [@Elastic Stack 6.4.1 and 5.6.12 security update](https://discuss.elastic.co/t/elastic-stack-6-4-1-and-5-6-12-security-update/149035):
>
> Kibana XSS issue (ESA-2018-14) Kibana versions 5.3.0 to 6.4.1 had a cross-site scripting (XSS) vulnerability via the source field formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users. Affected Versions Versions after 5.3.0 and before 6.4.1 or 5.6.12 Solutions and Mitigations Users should upgrade to Kibana version 6.4.1 or 5.6.12. There are no known workarounds for this issue. CVE ID: CVE-2018-3830 Elast…

Given that we cannot move our kibana to 6.4.1, I'd like to bring the patch for this on our code.  
(Or at least determine exactly in which conditions would this happen).

Could we have the GitHub link to the patch for this?  
Also, if we only have one user allowed for kibana, can this security issue happens?

I'd appreciate any info you can provide on this to allow me to secure the environment without need to pick up all the other changes.

---

<div class="post-metadata">

**Author:** ![jen-huang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jen-huang/32/74327_2.png) [@jen-huang](https://discuss.elastic.co/u/jen-huang)\
**Post date:** [January 15, 2019, 1:51am UTC](https://discuss.elastic.co/t/need-info-regarding-kibana-cross-site-scripting-xss-issue-esa-2018-14/164211/2 "2019-01-15T01:51:45Z")

</div>

Is it possible to upgrade to 5.6.12? That will also fix the vulnerability.

Here is the PR with code changes:

> <https://github.com/elastic/kibana/pull/22800>

---

<div class="post-metadata">

**Author:** ![fragatina](https://avatars.discourse-cdn.com/v4/letter/f/ccd318/32.png) [@fragatina](https://discuss.elastic.co/u/fragatina)\
**Post date:** [January 16, 2019, 10:10pm UTC](https://discuss.elastic.co/t/need-info-regarding-kibana-cross-site-scripting-xss-issue-esa-2018-14/164211/3 "2019-01-16T22:10:06Z")

</div>

Thanks jen-huang for providing the link to the patch of this issue.  
We are in the kibana 6 version line up but we cannot move to the 6.4.1.  
I'll patch the fix into our code to fix this. Thanks a lot!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 13, 2019, 10:10pm UTC](https://discuss.elastic.co/t/need-info-regarding-kibana-cross-site-scripting-xss-issue-esa-2018-14/164211/4 "2019-02-13T22:10:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
