First published: Fri Jun 14 2024(Updated: )
An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic | <7.17.22 | |
Elastic | >=8.0.0<8.14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-23442 has been classified as a medium severity vulnerability.
To fix CVE-2024-23442, upgrade Kibana to version 8.14.0 or to version 7.17.22 or later.
The impact of CVE-2024-23442 is that it can allow attackers to redirect users to arbitrary and potentially malicious websites.
CVE-2024-23442 affects all users of Kibana versions up to 7.17.22 and versions from 8.0.0 up to, but not including, 8.14.0.
To mitigate CVE-2024-23442, ensure that Kibana is updated to the recommended patched versions and educate users about the risks of clicking on suspicious URLs.