Description
With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any authenticated user could make requests to those services regardless of their own permissions.
Remediation
References
https://www.elastic.co/community/security
Related Vulnerabilities
CVE-2022-25209 Vulnerability in maven package org.jenkins-ci.plugins:sinatra-chef-builder
CVE-2020-16040 Vulnerability in npm package electron
CVE-2017-8028 Vulnerability in maven package org.springframework.ldap:spring-ldap-core
CVE-2019-1003034 Vulnerability in maven package org.jenkins-ci.plugins:job-dsl