kibana icon indicating copy to clipboard operation
kibana copied to clipboard

Vulnerability CVE-2024-4367 in pdfjs-dist library

Open fmulero opened this issue 5 months ago • 0 comments

Kibana version: 8.15.0

Elasticsearch version:

Server OS version: Latest image release

Browser version:

Browser OS version:

Original install method (e.g. download page, yum, from source, etc.):

Describe the bug:

Latest kibana image is apparently affected by CVE-2024-4367 because of pdfjs-dist library. Could you confirm whether Kibana is affected by this vulnerabilities and if so, are there plans to update the pdfjs-dist dependenciy?

Steps to reproduce:

$ trivy image kibana:8.15.0

Expected behavior: This CVE is gone.

Screenshots (if relevant):

Errors in browser console (if relevant):

Provide logs and/or server output (if relevant):

Any additional context:

fmulero avatar Aug 30 '24 16:08 fmulero