CVE-2020-10743: Elastic Kibana

Medium severity, CVSS 4.3. EPSS: 0.7% chance of exploitation in the next 30 days.

It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercept and manipulate requests. This flaw allows an attacker to trick a user into performing arbitrary actions in OCP's distribution of Kibana, such as clickjacking.

Affected products

  • Elastic Kibana: affected versions not specified
  • Red Hat Openshift Container Platform: version 3.11.286 only; version 4.6.1 only

Published 2021-06-02. Last modified 2026-06-17.