Elastic

Kibana

106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.22%
  • Veröffentlicht 16.06.2017 21:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

With X-Pack installed, Kibana versions before 5.3.1 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.

  • EPSS 0.38%
  • Veröffentlicht 16.06.2017 21:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Kibana versions prior to 5.2.1 configured for SSL client access, file descriptors will fail to be cleaned up after certain requests and will accumulate over time until the process crashes.

  • EPSS 0.34%
  • Veröffentlicht 05.06.2017 14:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Kibana version 5.4.0 was affected by a Cross Site Scripting (XSS) bug in the Time Series Visual Builder. This bug could allow an attacker to obtain sensitive information from Kibana users.

  • EPSS 0.34%
  • Veröffentlicht 05.06.2017 14:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

  • EPSS 0.16%
  • Veröffentlicht 07.12.2015 20:59:16
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Cross-site request forgery (CSRF) vulnerability in Elasticsearch Kibana before 4.1.3 and 4.2.x before 4.2.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

  • EPSS 0.24%
  • Veröffentlicht 15.06.2015 15:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Cross-site scripting (XSS) vulnerability in Elasticsearch Kibana 4.x before 4.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.