Description
The floragunn Search Guard plugin before 6.x-16 for Kibana allows URL injection for login redirects on the login page when basePath is set.
Remediation
References
https://github.com/floragunncom/search-guard-kibana-plugin/pull/140
https://docs.search-guard.com/latest/changelog-kibana-6.x-16
Related Vulnerabilities
CVE-2022-2047 Vulnerability in maven package org.eclipse.jetty:jetty-http
CVE-2018-9206 Vulnerability in maven package org.webjars.bower:blueimp-file-upload
CVE-2020-24025 Vulnerability in npm package node-sass
CVE-2018-20677 Vulnerability in maven package org.webjars:bootstrap-sass
CVE-2018-1320 Vulnerability in maven package org.apache.thrift:libthrift