First published: Fri Nov 18 2022(Updated: )
An open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously crafted URL, it could result in Kibana redirecting the user to an arbitrary website.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic Kibana | <6.8.16 | |
Elastic Kibana | >=7.0.0<7.13.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22141 is an open redirect flaw in Kibana versions before 7.13.0 and 6.8.16.
CVE-2021-22141 allows a logged in user to be redirected to an arbitrary website if they visit a maliciously crafted URL.
CVE-2021-22141 has a severity rating of medium (6.1).
To fix CVE-2021-22141, update Kibana to version 7.13.0 or 6.8.16.
More information about CVE-2021-22141 can be found at the following references: [link1](https://discuss.elastic.co/t/elastic-stack-7-13-0-and-6-8-16-security-update/273964), [link2](https://www.elastic.co/community/security/).