CVE-2016-10364

Source
https://cve.org/CVERecord?id=CVE-2016-10364
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-10364.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-10364
Published
2017-06-16T21:29:00.477Z
Modified
2026-07-08T14:58:11.991417Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any authenticated user could make requests to those services regardless of their own permissions.

References

Affected packages

Git / github.com/elastic/elasticsearch

Affected ranges

Type
GIT
Repo
https://github.com/elastic/elasticsearch
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:elastic:kibana:5.0.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:elastic:kibana:5.0.1:*:*:*:*:*:*:*"
    ],
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "5.0.0"
        },
        {
            "last_affected": "5.0.0"
        },
        {
            "introduced": "5.0.1"
        },
        {
            "last_affected": "5.0.1"
        }
    ]
}

Affected versions

5.*
5.0.0
5.0.1
v5.*
v5.0.0
v5.0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-10364.json"

Git / github.com/elastic/kibana

Affected ranges

Type
GIT
Repo
https://github.com/elastic/kibana
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:elastic:kibana:5.0.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:elastic:kibana:5.0.1:*:*:*:*:*:*:*"
    ],
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "5.0.0"
        },
        {
            "last_affected": "5.0.0"
        },
        {
            "introduced": "5.0.1"
        },
        {
            "last_affected": "5.0.1"
        }
    ]
}

Affected versions

5.*
5.0.0
5.0.1
v5.*
v5.0.0
v5.0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-10364.json"