Description
The floragunn Search Guard plugin before 6.x-16 for Kibana allows URL injection for login redirects on the login page when basePath is set.
Remediation
References
https://docs.search-guard.com/latest/changelog-kibana-6.x-16
https://github.com/floragunncom/search-guard-kibana-plugin/pull/140
Related Vulnerabilities
CVE-2022-22984 Vulnerability in npm package snyk-sbt-plugin
CVE-2022-28367 Vulnerability in maven package org.owasp.antisamy:antisamy
CVE-2022-35915 Vulnerability in npm package @openzeppelin/contracts-upgradeable
CVE-2017-18214 Vulnerability in maven package org.webjars.bowergithub.moment:moment
CVE-2020-5230 Vulnerability in maven package org.opencastproject:base