CVE-2016-1000218: CSRF
Kibana Reporting plugin version 2.4.0 is vulnerable to a CSRF vulnerability that could allow an attacker to generate superfluous reports whenever an authenticated Kibana user navigates to a specially-crafted page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1000218?
CVE-2016-1000218 is classified as a moderate severity vulnerability due to its ability to generate unauthorized reports.
How do I fix CVE-2016-1000218?
To fix CVE-2016-1000218, upgrade the Kibana Reporting plugin to a version that is not vulnerable, specifically version 2.4.1 or later.
What type of vulnerability is CVE-2016-1000218?
CVE-2016-1000218 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Kibana Reporting plugin.
Can CVE-2016-1000218 be exploited remotely?
Yes, CVE-2016-1000218 can be exploited remotely by an attacker targeting an authenticated user's session.
Is CVE-2016-1000218 specific to any software versions?
Yes, CVE-2016-1000218 specifically affects Elastic Kibana Reporting version 2.4.0.