Red Hat Bugzilla – Bug 1533359
CVE-2017-11479 kibana: XSS vulnerability in Timelion could allow an attacker obtain sensitive information or perform user actions
Last modified: 2018-01-11 02:30:33 EST
Kibana versions prior to 5.6.1 had a cross-site scripting (XSS) vulnerability in Timelion that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users. References: https://nvd.nist.gov/vuln/detail/CVE-2017-11479 https://discuss.elastic.co/t/x-pack-alerting-and-kibana-5-6-1-security-update/101884