Origin Validation Error in Kibana can lead to Server-Side Request Forgery via a forged Origin HTTP header processed by the Observability AI Assistant.
The product does not properly verify that the source of data or communication is valid.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Kibana | Elastic | 8.12.0 (including) | 8.19.7 (excluding) |
| Kibana | Elastic | 9.1.0 (including) | 9.1.7 (excluding) |
| Kibana | Elastic | 9.2.0 (including) | 9.2.0 (including) |