CVE-2017-8451: Medium severity elastic vulnerability
Published Jun 16, 2017
·Updated
With X-Pack installed, Kibana versions before 5.3.1 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.
Affected Software
1 affected component
Elastic Kibana<=5.3.0
Event History
Jun 16, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-8451?
CVE-2017-8451 has a medium severity rating due to its potential for exploitation via open redirect.
2
How do I fix CVE-2017-8451?
To fix CVE-2017-8451, upgrade Kibana to version 5.3.1 or later.
3
What versions of Kibana are affected by CVE-2017-8451?
CVE-2017-8451 affects all Kibana versions before 5.3.1.
4
What are the potential consequences of CVE-2017-8451?
Exploitation of CVE-2017-8451 could lead users to malicious sites, compromising their security.
5
Is there any workaround for CVE-2017-8451?
There are no known effective workarounds for CVE-2017-8451; updating is the recommended action.