CVE-2022-38779

Source
https://cve.org/CVERecord?id=CVE-2022-38779
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-38779.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-38779
Published
2023-02-21T00:00:00Z
Modified
2026-07-22T02:51:12.234172Z
Summary
[none]
Details

An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.

Database specific
{
    "cwe_ids": [
        "CWE-601"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/38xxx/CVE-2022-38779.json",
    "cna_assigner": "elastic"
}
References

Affected packages

Git / github.com/elastic/elasticsearch

Affected ranges

Type
GIT
Repo
https://github.com/elastic/elasticsearch
Events
Database specific
{
    "cpe": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "7.0.0"
        },
        {
            "fixed": "7.17.9"
        },
        {
            "introduced": "8.0.0"
        },
        {
            "fixed": "8.6.2"
        }
    ]
}

Database specific

vanir_signatures_modified
"2026-07-22T02:51:12Z"
vanir_signatures
[
    {
        "signature_type": "Function",
        "target": {
            "file": "qa/rolling-upgrade/src/test/java/org/elasticsearch/upgrades/FeatureUpgradeIT.java",
            "function": "testGetFeatureUpgradeStatus"
        },
        "deprecated": false,
        "source": "https://github.com/elastic/elasticsearch/commit/2d58d0f136141f03239816a4e360a8d17b6d8f29",
        "id": "CVE-2022-38779-130872d3",
        "signature_version": "v1",
        "digest": {
            "function_hash": "186257870524567512418113347536776731155",
            "length": 2559.0
        }
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "qa/rolling-upgrade/src/test/java/org/elasticsearch/upgrades/FeatureUpgradeIT.java"
        },
        "deprecated": false,
        "source": "https://github.com/elastic/elasticsearch/commit/2d58d0f136141f03239816a4e360a8d17b6d8f29",
        "id": "CVE-2022-38779-1346e405",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "62039961999204242076671245683234696658",
                "57307489175235936928403513192876445338",
                "147220359592716756819033580786414299221",
                "246638575288066624726728916924764699302",
                "185159517116227614509960132440813431242",
                "112133366805059875235254301618258464771"
            ],
            "threshold": 0.9
        }
    },
    {
        "signature_type": "Function",
        "target": {
            "file": "server/src/main/java/org/elasticsearch/action/admin/cluster/migration/TransportGetFeatureUpgradeStatusAction.java",
            "function": "TransportGetFeatureUpgradeStatusAction"
        },
        "deprecated": false,
        "source": "https://github.com/elastic/elasticsearch/commit/2d58d0f136141f03239816a4e360a8d17b6d8f29",
        "id": "CVE-2022-38779-22a2c7a5",
        "signature_version": "v1",
        "digest": {
            "function_hash": "5839263564734697771203486732478121420",
            "length": 300.0
        }
    },
    {
        "signature_type": "Function",
        "target": {
            "file": "modules/reindex/src/internalClusterTest/java/org/elasticsearch/migration/AbstractFeatureMigrationIntegTest.java",
            "function": "setup"
        },
        "deprecated": false,
        "source": "https://github.com/elastic/elasticsearch/commit/2d58d0f136141f03239816a4e360a8d17b6d8f29",
        "id": "CVE-2022-38779-4fe2c2db",
        "signature_version": "v1",
        "digest": {
            "function_hash": "270655356682581275791571300696532176668",
            "length": 337.0
        }
    },
    {
        "signature_type": "Function",
        "target": {
            "file": "test/test-clusters/src/main/java/org/elasticsearch/test/cluster/local/LocalClusterFactory.java",
            "function": "start"
        },
        "deprecated": false,
        "source": "https://github.com/elastic/elasticsearch/commit/ef48222227ee6b9e70e502f0f0daa52435ee634d",
        "id": "CVE-2022-38779-7126c131",
        "signature_version": "v1",
        "digest": {
            "function_hash": "253424462771408036179652827713905704388",
            "length": 796.0
        }
    },
    {
        "signature_type": "Function",
        "target": {
            "file": "server/src/test/java/org/elasticsearch/action/admin/cluster/migration/TransportGetFeatureUpgradeStatusActionTests.java",
            "function": "testGetIndexInfos"
        },
        "deprecated": false,
        "source": "https://github.com/elastic/elasticsearch/commit/2d58d0f136141f03239816a4e360a8d17b6d8f29",
        "id": "CVE-2022-38779-7fe03702",
        "signature_version": "v1",
        "digest": {
            "function_hash": "304632466252487624428809808854553247493",
            "length": 507.0
        }
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "server/src/test/java/org/elasticsearch/action/admin/cluster/migration/TransportGetFeatureUpgradeStatusActionTests.java"
        },
        "deprecated": false,
        "source": "https://github.com/elastic/elasticsearch/commit/2d58d0f136141f03239816a4e360a8d17b6d8f29",
        "id": "CVE-2022-38779-890eb0d9",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "304198583092620291857766682009500723331",
                "93532374563921044930347651622391703039",
                "154448412257907399315648182016401336247",
                "307593714635983191160574299265729770438",
                "275415183183275088699183102049187506032",
                "268387595942067166965926131962911238158",
                "251864851443250010333070596045517806039",
                "77139260241216743985620092091127670485",
                "217428350190090981022896446737746675007",
                "154220734962593317291892671209024157273",
                "255066945339245079419294192694320204113",
                "184734217222970944327959224278876882049",
                "150524077735285677048918570159443093951",
                "287458558688669801764240494434728705245",
                "137898569842873787913950811566316947724",
                "88937017370909443889470675460931461494",
                "225404232148617784443053188936048544119"
            ],
            "threshold": 0.9
        }
    },
    {
        "signature_type": "Function",
        "target": {
            "file": "server/src/test/java/org/elasticsearch/action/admin/cluster/migration/TransportGetFeatureUpgradeStatusActionTests.java",
            "function": "testGetFeatureStatus"
        },
        "deprecated": false,
        "source": "https://github.com/elastic/elasticsearch/commit/2d58d0f136141f03239816a4e360a8d17b6d8f29",
        "id": "CVE-2022-38779-a6f12d5b",
        "signature_version": "v1",
        "digest": {
            "function_hash": "320088857579918567607363477088866754164",
            "length": 377.0
        }
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "test/test-clusters/src/main/java/org/elasticsearch/test/cluster/local/LocalClusterFactory.java"
        },
        "deprecated": false,
        "source": "https://github.com/elastic/elasticsearch/commit/ef48222227ee6b9e70e502f0f0daa52435ee634d",
        "id": "CVE-2022-38779-adc0c667",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "328783117535713225377078719017895934894",
                "218962949926834068220532377964025986269",
                "238873534878858557428085250597699491727",
                "63077107520883219164804643621703692733",
                "66788853691360615475714774552204583495",
                "235984818079188790404255208318579500458",
                "122272605970820100222461377080912574433",
                "218240151183537112180691515958244680759",
                "74982244718916453758071782997683156102",
                "338998086836341997413146815199410074826",
                "183545008697450786058075772372139794156",
                "14150877025559646740082274151309028560",
                "165346515570815984485986167003908280712",
                "133921416539802914293419784636618607124",
                "335194391246084399905387481005122256392",
                "287472674007991101034770761473652905017",
                "32088835855662654741678314163880302816",
                "1737611290573491832151774625136018650",
                "41302012581605084517150417062557235387",
                "111850715464812135337423374498156388695",
                "190938082947915130398453485194117962279",
                "200222680760379930174317775945798073524"
            ],
            "threshold": 0.9
        }
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "modules/reindex/src/internalClusterTest/java/org/elasticsearch/migration/AbstractFeatureMigrationIntegTest.java"
        },
        "deprecated": false,
        "source": "https://github.com/elastic/elasticsearch/commit/2d58d0f136141f03239816a4e360a8d17b6d8f29",
        "id": "CVE-2022-38779-b559d63c",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "248047417370916315439752865592395175956",
                "315983797586265415583834353066933331736",
                "312013460032099731481871450009937804796",
                "143767621828807655676638691579891705261",
                "136448671909715594618604443327799286145",
                "330588128067386814695626037070539070387",
                "255437223768996420483918861391573387200",
                "228797384174437050426060611486730326156",
                "179948730281860460728605003216012652508",
                "146910777192892687368175157311193383978",
                "252180710832146766022433591571011194129"
            ],
            "threshold": 0.9
        }
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "server/src/main/java/org/elasticsearch/action/admin/cluster/migration/TransportGetFeatureUpgradeStatusAction.java"
        },
        "deprecated": false,
        "source": "https://github.com/elastic/elasticsearch/commit/2d58d0f136141f03239816a4e360a8d17b6d8f29",
        "id": "CVE-2022-38779-bc84fa57",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "258489881906712820950852082223712412471",
                "224427820974090640552193107358110666765",
                "116392234902123390529359812958365300789",
                "154801713849791830830675898279228738538",
                "90972928435560328054350297142577549930",
                "229580121594427613184356826595104767736",
                "197909314958452003170714354142190779122",
                "131167841232331831811428081488851824861"
            ],
            "threshold": 0.9
        }
    },
    {
        "signature_type": "Function",
        "target": {
            "file": "server/src/test/java/org/elasticsearch/action/admin/cluster/migration/TransportGetFeatureUpgradeStatusActionTests.java",
            "function": "getClusterState"
        },
        "deprecated": false,
        "source": "https://github.com/elastic/elasticsearch/commit/2d58d0f136141f03239816a4e360a8d17b6d8f29",
        "id": "CVE-2022-38779-eed8a9d9",
        "signature_version": "v1",
        "digest": {
            "function_hash": "19156491380485715914822349670737399228",
            "length": 671.0
        }
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-38779.json"

Git / github.com/elastic/kibana

Affected ranges

Type
GIT
Repo
https://github.com/elastic/kibana
Events
Database specific
{
    "cpe": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "7.0.0"
        },
        {
            "fixed": "7.17.9"
        },
        {
            "introduced": "8.0.0"
        },
        {
            "fixed": "8.6.2"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-38779.json"