Description
Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link in the Kibana domain that redirects to an arbitrary website.
Remediation
References
https://www.elastic.co/community/security
Related Vulnerabilities
CVE-2023-0100 Vulnerability in maven package org.eclipse.birt:org.eclipse.birt.report.viewer
CVE-2020-2094 Vulnerability in maven package org.jenkins-ci.plugins:cloudbees-jenkins-advisor
CVE-2015-8857 Vulnerability in maven package org.webjars.npm:uglify-js
CVE-2020-5408 Vulnerability in maven package org.springframework.security:spring-security-core
CVE-2016-4436 Vulnerability in maven package org.apache.struts:struts2-rest-plugin