Bug 1538801 (CVE-2017-8451) - CVE-2017-8451 kibana: open redirect on the login page (ESA-2017-04 )
Summary: CVE-2017-8451 kibana: open redirect on the login page (ESA-2017-04 )
Keywords:
Status: CLOSED WONTFIX
Alias: CVE-2017-8451
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1538802
Blocks: 1538798
TreeView+ depends on / blocked
 
Reported: 2018-01-25 21:16 UTC by Laura Pardo
Modified: 2019-09-29 14:31 UTC (History)
22 users (show)

Fixed In Version: kibana 5.3.1
Clone Of:
Environment:
Last Closed: 2019-06-08 03:38:21 UTC
Embargoed:


Attachments (Terms of Use)

Description Laura Pardo 2018-01-25 21:16:36 UTC
With X-Pack installed, Kibana versions before 5.3.1 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website. Shield versions for Kibana prior to 2.4.5 are also affected. 

References:
https://www.elastic.co/community/security

Comment 1 Laura Pardo 2018-01-25 21:17:13 UTC
Created puppet-kibana3 tracking bugs for this issue:

Affects: openstack-rdo [bug 1538802]


Note You need to log in before you can comment on or make changes to this bug.