Bug 2292843 (CVE-2024-23442)

Summary: CVE-2024-23442 kibana: Open Redirect Issue
Product: [Other] Security Response Reporter: Patrick Del Bello <pdelbell>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: caswilli, eglynn, jcantril, jjoyce, jschluet, kaycoth, lhh, lsvaty, mburns, mgarciac, mwringe, periklis, pgrist, rhos-maint, slinaber, tvignaud
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: kibana 7.17.22, kibana 8.14.0 Doc Type: ---
Doc Text:
An open redirect flaw was found in Kibana. This issue can lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2293145, 2293146    
Bug Blocks: 2292842    

Description Patrick Del Bello 2024-06-18 04:26:27 UTC
An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.

https://discuss.elastic.co/t/kibana-8-14-0-7-17-22-security-update/361502