CVE-2016-10365: Medium severity Elastic Kibana vulnerability
Published Jun 16, 2017
·Updated
Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link in the Kibana domain that redirects to an arbitrary website.
Affected Software
2 affected components
Elastic Kibana<=4.6.2
Elastic Kibana<=5.0.0
Event History
Jun 16, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-10365?
CVE-2016-10365 has a medium severity rating due to its potential for exploitation through open redirects.
2
How do I fix CVE-2016-10365?
To fix CVE-2016-10365, upgrade Kibana to version 4.6.3 or 5.0.1 or later.
3
What is the impact of CVE-2016-10365?
The impact of CVE-2016-10365 allows attackers to redirect users to arbitrary external websites, potentially leading to phishing attacks.
4
Which versions of Kibana are affected by CVE-2016-10365?
CVE-2016-10365 affects Kibana versions prior to 4.6.3 and 5.0.1.
5
Is there a workaround for CVE-2016-10365?
There is no effective workaround for CVE-2016-10365; upgrading to a patched version is necessary.