Safely handling user input in Elasticsearch documents #58040
Labels
Feature:Hardening
Harding of Kibana from a security perspective
R&D
Research and development ticket (not meant to produce code, but to make a decision)
Team:Security
Team focused on: Auth, Users, Roles, Spaces, Audit Logging, and more!
Elasticsearch documents can commonly contain data that is specified by end-users, and shouldn't be trusted. We should figure out how to safely handle these documents without exposing ourselves to the general pitfalls that come along with unconstrained user input.
The text was updated successfully, but these errors were encountered: