SB2017120818 - Multiple vulnerabilities in Kibana



SB2017120818 - Multiple vulnerabilities in Kibana

Published: December 8, 2017 Updated: August 8, 2020

Security Bulletin ID SB2017120818
Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Cross-site scripting (CVE-ID: CVE-2017-11481)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Kibana versions prior to 6.0.1 and 5.6.5 had a cross-site scripting (XSS) vulnerability via URL fields that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.


2) Open redirect (CVE-ID: CVE-2017-11482)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

The Kibana fix for CVE-2017-8451 was found to be incomplete. With X-Pack installed, Kibana versions before 6.0.1 and 5.6.5 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.


Remediation

Install update from vendor's website.