CVE-2018-3819: Medium severity elastic vulnerability
The fix in Kibana for ESA-2017-23 was incomplete. With X-Pack security enabled, Kibana versions before 6.1.3 and 5.6.7 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-3819?
CVE-2018-3819 is an open redirect vulnerability in Kibana versions before 6.1.3 and 5.6.7 with X-Pack security enabled.
How does CVE-2018-3819 affect Kibana?
CVE-2018-3819 affects Kibana versions before 6.1.3 and 5.6.7 with X-Pack security enabled, allowing attackers to craft malicious links that redirect users to arbitrary websites.
What is the severity of CVE-2018-3819?
CVE-2018-3819 has a severity value of 6.1, which is considered medium.
How can I fix CVE-2018-3819 vulnerability?
To fix CVE-2018-3819, it is recommended to upgrade Kibana to version 6.1.3 or above.
Where can I find more information about CVE-2018-3819?
You can find more information about CVE-2018-3819 on the Elastic discussion forum: [link](https://discuss.elastic.co/t/elastic-stack-6-1-3-and-5-6-7-security-update/117683).