Open redirect in Kibana - CVE-2018-3819
Published: April 3, 2018
Kibana
Detailed vulnerability description
The disclosed vulnerability allows a remote attacker to conduct an open redirect attack.
The vulnerability exists in the login page due to an incomplete fix for another vulnerability identified as CVE-2017-11482. A remote attacker can trick the victim into following a specially crafted link, redirect the user to a malicious website and conduct further attacks or perform arbitrary actions.