Description
The floragunn Search Guard plugin before 6.x-16 for Kibana allows URL injection for login redirects on the login page when basePath is set.
Remediation
References
https://docs.search-guard.com/latest/changelog-kibana-6.x-16
https://github.com/floragunncom/search-guard-kibana-plugin/pull/140
Related Vulnerabilities
CVE-2016-10735 Vulnerability in maven package li.rudin.mavenjs:bootstrap
CVE-2021-28092 Vulnerability in maven package org.webjars.npm:is-svg
CVE-2023-46651 Vulnerability in maven package io.jenkins.plugins:warnings-ng
CVE-2021-21307 Vulnerability in maven package org.lucee:lucee
CVE-2018-20676 Vulnerability in maven package org.webjars.bowergithub.angular-ui:bootstrap