Back

HIGH

kibana: Session hijack via stealing cookies and auth headers from log ESA-2016-04

Published Jun 16, 2017

Description

Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers could be written to the log files. This information could be used to hijack sessions of other users when using Kibana behind some form of authentication such as Shield.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 16, 2017
Updated Aug 6, 2024
Reserved Sep 12, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 3, 2016