Description
With X-Pack installed, Kibana versions before 5.3.1 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.
Remediation
References
https://www.elastic.co/community/security
Related Vulnerabilities
CVE-2023-30542 Vulnerability in npm package @openzeppelin/contracts
CVE-2018-11788 Vulnerability in maven package org.apache.karaf.specs:org.apache.karaf.specs.java.xml
CVE-2018-14041 Vulnerability in maven package org.webjars:bootstrap
CVE-2020-9480 Vulnerability in maven package org.apache.spark:spark-network-common_2.10
CVE-2019-12423 Vulnerability in maven package org.apache.cxf:cxf-rt-rs-security-jose