kibana: open redirect on the login page
Published Mar 30, 2018
6.1
MEDIUMCVSS 3.0
EPSS 0.84%
Description
The fix in Kibana for ESA-2017-23 was incomplete. With X-Pack security enabled, Kibana versions before 6.1.3 and 5.6.7 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.
Affected products
-
- Version All versions before 6.1.3 and 5.6.7StatusaffectedConstraints-
- Version
No data.
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational Tools
kibana
Not affected
Red Hat OpenShift Enterprise 3
kibana
Affected
Red Hat OpenStack Platform 8 (Liberty) Operational Tools
kibana
Not affected
Red Hat OpenStack Platform 9 (Mitaka) Operational Tools
kibana
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational Tools | kibana | Not affected | n/a |
| Red Hat OpenShift Enterprise 3 | kibana | Affected | n/a |
| Red Hat OpenStack Platform 8 (Liberty) Operational Tools | kibana | Not affected | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) Operational Tools | kibana | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the versions of kibana as shipped with Red Hat OpenShift Enterprise Linux. Red Hat Product Security has rated this issue as having security impact of Moderate. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
References (5)
- https://access.redhat.com/security/cve/CVE-2018-3819 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1552117 Issue Tracking
- https://discuss.elastic.co/t/elastic-stack-6-1-3-and-5-6-7-security-update/117683 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-3819
- https://www.cve.org/CVERecord?id=CVE-2018-3819
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2018-3819 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1552117 | Issue Tracking | |
| https://discuss.elastic.co/t/elastic-stack-6-1-3-and-5-6-7-security-update/117683 | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-3819 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-3819 |
Change history (0)
No recorded changes yet.