GHSA-rj62-3vmp-2f6j
GitHub Security Advisory
⚠ Unreviewed
LOW
Has CVE
Advisory Details
It was discovered that Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host to load internal files ending in the .pbf extension.
Related CVEs
Key Information
2.5
/10
Dataset
Last updated: September 29, 2025 6:31 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.