CVE-2024-23442: Kibana open redirect issue
Published Jun 14, 2024
·Updated
An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.
Affected Software
2 affected components
Elastic Kibana<7.17.22
Elastic Kibana>=8.0.0<8.14.0
Event History
Jun 14, 2024
CVE Published
via MITRE·02:26 PM
Data Sourced
via MITRE·02:26 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-23442?
CVE-2024-23442 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2024-23442?
To fix CVE-2024-23442, upgrade Kibana to version 8.14.0 or to version 7.17.22 or later.
3
What is the impact of CVE-2024-23442?
The impact of CVE-2024-23442 is that it can allow attackers to redirect users to arbitrary and potentially malicious websites.
4
Who is affected by CVE-2024-23442?
CVE-2024-23442 affects all users of Kibana versions up to 7.17.22 and versions from 8.0.0 up to, but not including, 8.14.0.
5
What measures can be taken to mitigate CVE-2024-23442?
To mitigate CVE-2024-23442, ensure that Kibana is updated to the recommended patched versions and educate users about the risks of clicking on suspicious URLs.