Description
The floragunn Search Guard plugin before 6.x-16 for Kibana allows URL injection for login redirects on the login page when basePath is set.
Remediation
References
https://docs.search-guard.com/latest/changelog-kibana-6.x-16
https://github.com/floragunncom/search-guard-kibana-plugin/pull/140
Related Vulnerabilities
CVE-2022-24785 Vulnerability in maven package org.webjars.bower:moment
CVE-2022-31089 Vulnerability in npm package parse-server
CVE-2023-36820 Vulnerability in maven package io.micronaut.security:micronaut-security-oauth2
CVE-2021-42697 Vulnerability in maven package com.typesafe.akka:akka-http_2.12
CVE-2023-33201 Vulnerability in maven package org.bouncycastle:bcprov-jdk18on