Kibana versions prior to 5.6.1 had a cross-site scripting (XSS) vulnerability in Timelion that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "5.0.0"
},
{
"introduced": "0"
},
{
"last_affected": "5.0.1"
},
{
"introduced": "0"
},
{
"last_affected": "5.0.2"
},
{
"introduced": "0"
},
{
"last_affected": "5.1.1"
},
{
"introduced": "0"
},
{
"last_affected": "5.1.2"
},
{
"introduced": "0"
},
{
"last_affected": "5.2.0"
},
{
"introduced": "0"
},
{
"last_affected": "5.2.1"
},
{
"introduced": "0"
},
{
"last_affected": "5.2.2"
},
{
"introduced": "0"
},
{
"last_affected": "5.3.0"
},
{
"introduced": "0"
},
{
"last_affected": "5.3.1"
},
{
"introduced": "0"
},
{
"last_affected": "5.3.2"
},
{
"introduced": "0"
},
{
"last_affected": "5.3.3"
},
{
"introduced": "0"
},
{
"last_affected": "5.4.0"
},
{
"introduced": "0"
},
{
"last_affected": "5.4.1"
},
{
"introduced": "0"
},
{
"last_affected": "5.4.2"
},
{
"introduced": "0"
},
{
"last_affected": "5.4.3"
},
{
"introduced": "0"
},
{
"last_affected": "5.5.0"
},
{
"introduced": "0"
},
{
"last_affected": "5.5.1"
},
{
"introduced": "0"
},
{
"last_affected": "5.5.2"
},
{
"introduced": "0"
},
{
"last_affected": "5.5.3"
},
{
"introduced": "0"
},
{
"last_affected": "5.6.0"
},
{
"introduced": "0"
},
{
"last_affected": "5.1.0"
}
]
}