Description
Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link in the Kibana domain that redirects to an arbitrary website.
Remediation
References
https://www.elastic.co/community/security
Related Vulnerabilities
CVE-2023-22602 Vulnerability in maven package org.apache.shiro:shiro-spring-boot-starter
CVE-2021-21694 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2019-11272 Vulnerability in maven package org.springframework.security:spring-security-core
CVE-2019-10290 Vulnerability in maven package org.jenkins-ci.plugins:netsparker-cloud-scan
CVE-2015-0227 Vulnerability in maven package org.apache.wss4j:wss4j-ws-security-dom