Description
The floragunn Search Guard plugin before 6.x-16 for Kibana allows URL injection for login redirects on the login page when basePath is set.
Remediation
References
https://docs.search-guard.com/latest/changelog-kibana-6.x-16
https://github.com/floragunncom/search-guard-kibana-plugin/pull/140
Related Vulnerabilities
CVE-2022-39248 Vulnerability in maven package org.matrix.android:matrix-android-sdk2
CVE-2018-11784 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2022-41937 Vulnerability in maven package org.xwiki.platform:xwiki-platform-filter-ui
CVE-2023-30525 Vulnerability in maven package org.jenkins-ci.plugins:reportportal
CVE-2022-43401 Vulnerability in maven package org.jenkins-ci.plugins:script-security