The fix in Kibana for ESA-2017-23 was incomplete. With X-Pack security enabled, Kibana versions before 6.1.3 and 5.6.7 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.
{
"cpe": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "5.6.7"
},
{
"introduced": "6.0.0"
},
{
"fixed": "6.1.3"
}
]
}{
"cpe": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "5.6.7"
},
{
"introduced": "6.0.0"
},
{
"fixed": "6.1.3"
}
]
}