First published: Fri Jun 16 2017(Updated: )
With X-Pack installed, Kibana versions before 5.3.1 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic Kibana | <=5.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8451 has a medium severity rating due to its potential for exploitation via open redirect.
To fix CVE-2017-8451, upgrade Kibana to version 5.3.1 or later.
CVE-2017-8451 affects all Kibana versions before 5.3.1.
Exploitation of CVE-2017-8451 could lead users to malicious sites, compromising their security.
There are no known effective workarounds for CVE-2017-8451; updating is the recommended action.