Description
Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link in the Kibana domain that redirects to an arbitrary website.
Remediation
References
https://www.elastic.co/community/security
Related Vulnerabilities
CVE-2019-10288 Vulnerability in maven package de.e-nexus:jabber-server-plugin
CVE-2023-24444 Vulnerability in maven package org.jenkins-ci.plugins:openid
CVE-2016-0783 Vulnerability in maven package org.apache.openmeetings:openmeetings-install
CVE-2019-1003003 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2021-39231 Vulnerability in maven package org.apache.ozone:ozone-main