Description
The floragunn Search Guard plugin before 6.x-16 for Kibana allows URL injection for login redirects on the login page when basePath is set.
Remediation
References
https://docs.search-guard.com/latest/changelog-kibana-6.x-16
https://github.com/floragunncom/search-guard-kibana-plugin/pull/140
Related Vulnerabilities
CVE-2022-24816 Vulnerability in maven package it.geosolutions.jaiext.jiffle:jt-jiffle-language
CVE-2022-36077 Vulnerability in npm package electron
CVE-2020-7730 Vulnerability in npm package bestzip
CVE-2018-19361 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2020-26291 Vulnerability in maven package org.webjars.npm:urijs