First published: Fri Jun 16 2017(Updated: )
Kibana Reporting plugin version 2.4.0 is vulnerable to a CSRF vulnerability that could allow an attacker to generate superfluous reports whenever an authenticated Kibana user navigates to a specially-crafted page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kibana Reporting | =2.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1000218 is classified as a moderate severity vulnerability due to its ability to generate unauthorized reports.
To fix CVE-2016-1000218, upgrade the Kibana Reporting plugin to a version that is not vulnerable, specifically version 2.4.1 or later.
CVE-2016-1000218 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Kibana Reporting plugin.
Yes, CVE-2016-1000218 can be exploited remotely by an attacker targeting an authenticated user's session.
Yes, CVE-2016-1000218 specifically affects Elastic Kibana Reporting version 2.4.0.