The vendor explicitly identifies these products as affected by this CVE.
- openshift4/ose-logging-kibana6 as a component of Red Hat OpenShift Container Platform 4
- Summary
- A flaw was found in nodejs-vega. An attacker, using a specially crafted Vega expression, could execute a cross-side scripting attack on a victim's machine allowing them to execute arbitrary JavaScript. The highest threat from this vulnerability is to data confidentiality and integrity.
- Remediation
- For Kibana which does contain the dependency vega, it is possible to turn of vega visualizations with `vega.enabled: false` in the kibana.yml
