CVE-2018-17245
- EPSS 0.32%
- Veröffentlicht 20.12.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:54:09
Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating PDF reports. If a report requests external resources plaintext credentials are included in the HTTP request tha...
CVE-2018-17246
- EPSS 93.77%
- Veröffentlicht 20.12.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:54:09
Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code. This could possibly lead to a...
CVE-2018-3830
- EPSS 0.71%
- Veröffentlicht 19.09.2018 19:29:01
- Zuletzt bearbeitet 21.11.2024 04:06:07
Kibana versions 5.3.0 to 6.4.1 had a cross-site scripting (XSS) vulnerability via the source field formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
CVE-2018-3821
- EPSS 0.38%
- Veröffentlicht 30.03.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:06:06
Kibana versions after 5.1.1 and before 5.6.7 and 6.1.3 had a cross-site scripting (XSS) vulnerability in the tag cloud visualization that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other K...
CVE-2018-3820
- EPSS 0.35%
- Veröffentlicht 30.03.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:06:05
Kibana versions after 6.1.0 and before 6.1.3 had a cross-site scripting (XSS) vulnerability in labs visualizations that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
CVE-2018-3819
- EPSS 0.21%
- Veröffentlicht 30.03.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:06:05
The fix in Kibana for ESA-2017-23 was incomplete. With X-Pack security enabled, Kibana versions before 6.1.3 and 5.6.7 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary ...
CVE-2018-3818
- EPSS 0.38%
- Veröffentlicht 30.03.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:06:05
Kibana versions 5.1.1 to 6.1.2 and 5.6.6 had a cross-site scripting (XSS) vulnerability via the colored fields formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
CVE-2017-11482
- EPSS 0.2%
- Veröffentlicht 08.12.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The Kibana fix for CVE-2017-8451 was found to be incomplete. With X-Pack installed, Kibana versions before 6.0.1 and 5.6.5 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitr...
CVE-2017-11481
- EPSS 0.27%
- Veröffentlicht 08.12.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Kibana versions prior to 6.0.1 and 5.6.5 had a cross-site scripting (XSS) vulnerability via URL fields that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
CVE-2017-11479
- EPSS 0.39%
- Veröffentlicht 29.09.2017 01:34:48
- Zuletzt bearbeitet 20.04.2025 01:37:25
Kibana versions prior to 5.6.1 had a cross-site scripting (XSS) vulnerability in Timelion that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.