The floragunn Search Guard plugin before 6.x-16 for Kibana allows URL injection for login redirects on the login page when basePath is set.
{ "versions": [ { "introduced": "0" }, { "fixed": "6.3.0-16" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-20698.json"