← Back to CVE List

CVE-2021-22136

Published: 2021-05-13T18:15Z
Last Modified: 2024-11-21T05:49Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In Kibana versions before 7.12.0 and 6.8.15 a flaw in the session timeout was discovered where the xpack.security.session.idleTimeout setting is not being respected. This was caused by background polling activities unintentionally extending authenticated users sessions, preventing a user session from timing out. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt