Skip to content

Whitelist domains for dev_tools/console?load_from= #8851

@synhershko

Description

@synhershko

Consider the following: localhost:5601/app/kibana#/dev_tools/console?load_from=malicious_script.json

Kibana probably needs a whitelist for domains to load from to protect against malicious usage (even though Console doesn't run the Sense scripts automatically). As an attacker I can easily trick the user to do stuff that he will regret later and I believe Kibana at least shouldn't make it that easy for them.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Feature:ConsoleDev Tools Console FeatureFeature:Dev ToolsTeam:Kibana ManagementDev Tools, Index Management, Upgrade Assistant, ILM, Ingest Node Pipelines, and more t//

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions