First published: Fri Mar 30 2018(Updated: )
The fix in Kibana for ESA-2017-23 was incomplete. With X-Pack security enabled, Kibana versions before 6.1.3 and 5.6.7 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic Kibana | <5.6.7 | |
Elastic Kibana | >=6.0.0<6.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-3819 is an open redirect vulnerability in Kibana versions before 6.1.3 and 5.6.7 with X-Pack security enabled.
CVE-2018-3819 affects Kibana versions before 6.1.3 and 5.6.7 with X-Pack security enabled, allowing attackers to craft malicious links that redirect users to arbitrary websites.
CVE-2018-3819 has a severity value of 6.1, which is considered medium.
To fix CVE-2018-3819, it is recommended to upgrade Kibana to version 6.1.3 or above.
You can find more information about CVE-2018-3819 on the Elastic discussion forum: [link](https://discuss.elastic.co/t/elastic-stack-6-1-3-and-5-6-7-security-update/117683).