First published: Fri Jun 16 2017(Updated: )
Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link in the Kibana domain that redirects to an arbitrary website.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic | <=4.6.2 | |
Elastic | <=5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10365 has a medium severity rating due to its potential for exploitation through open redirects.
To fix CVE-2016-10365, upgrade Kibana to version 4.6.3 or 5.0.1 or later.
The impact of CVE-2016-10365 allows attackers to redirect users to arbitrary external websites, potentially leading to phishing attacks.
CVE-2016-10365 affects Kibana versions prior to 4.6.3 and 5.0.1.
There is no effective workaround for CVE-2016-10365; upgrading to a patched version is necessary.