An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.
{
"cwe_ids": [
"CWE-601"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/38xxx/CVE-2022-38779.json",
"cna_assigner": "elastic"
}"2026-07-22T02:51:12Z"
[
{
"signature_type": "Function",
"target": {
"file": "qa/rolling-upgrade/src/test/java/org/elasticsearch/upgrades/FeatureUpgradeIT.java",
"function": "testGetFeatureUpgradeStatus"
},
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/2d58d0f136141f03239816a4e360a8d17b6d8f29",
"id": "CVE-2022-38779-130872d3",
"signature_version": "v1",
"digest": {
"function_hash": "186257870524567512418113347536776731155",
"length": 2559.0
}
},
{
"signature_type": "Line",
"target": {
"file": "qa/rolling-upgrade/src/test/java/org/elasticsearch/upgrades/FeatureUpgradeIT.java"
},
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/2d58d0f136141f03239816a4e360a8d17b6d8f29",
"id": "CVE-2022-38779-1346e405",
"signature_version": "v1",
"digest": {
"line_hashes": [
"62039961999204242076671245683234696658",
"57307489175235936928403513192876445338",
"147220359592716756819033580786414299221",
"246638575288066624726728916924764699302",
"185159517116227614509960132440813431242",
"112133366805059875235254301618258464771"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"target": {
"file": "server/src/main/java/org/elasticsearch/action/admin/cluster/migration/TransportGetFeatureUpgradeStatusAction.java",
"function": "TransportGetFeatureUpgradeStatusAction"
},
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/2d58d0f136141f03239816a4e360a8d17b6d8f29",
"id": "CVE-2022-38779-22a2c7a5",
"signature_version": "v1",
"digest": {
"function_hash": "5839263564734697771203486732478121420",
"length": 300.0
}
},
{
"signature_type": "Function",
"target": {
"file": "modules/reindex/src/internalClusterTest/java/org/elasticsearch/migration/AbstractFeatureMigrationIntegTest.java",
"function": "setup"
},
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/2d58d0f136141f03239816a4e360a8d17b6d8f29",
"id": "CVE-2022-38779-4fe2c2db",
"signature_version": "v1",
"digest": {
"function_hash": "270655356682581275791571300696532176668",
"length": 337.0
}
},
{
"signature_type": "Function",
"target": {
"file": "test/test-clusters/src/main/java/org/elasticsearch/test/cluster/local/LocalClusterFactory.java",
"function": "start"
},
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/ef48222227ee6b9e70e502f0f0daa52435ee634d",
"id": "CVE-2022-38779-7126c131",
"signature_version": "v1",
"digest": {
"function_hash": "253424462771408036179652827713905704388",
"length": 796.0
}
},
{
"signature_type": "Function",
"target": {
"file": "server/src/test/java/org/elasticsearch/action/admin/cluster/migration/TransportGetFeatureUpgradeStatusActionTests.java",
"function": "testGetIndexInfos"
},
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/2d58d0f136141f03239816a4e360a8d17b6d8f29",
"id": "CVE-2022-38779-7fe03702",
"signature_version": "v1",
"digest": {
"function_hash": "304632466252487624428809808854553247493",
"length": 507.0
}
},
{
"signature_type": "Line",
"target": {
"file": "server/src/test/java/org/elasticsearch/action/admin/cluster/migration/TransportGetFeatureUpgradeStatusActionTests.java"
},
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/2d58d0f136141f03239816a4e360a8d17b6d8f29",
"id": "CVE-2022-38779-890eb0d9",
"signature_version": "v1",
"digest": {
"line_hashes": [
"304198583092620291857766682009500723331",
"93532374563921044930347651622391703039",
"154448412257907399315648182016401336247",
"307593714635983191160574299265729770438",
"275415183183275088699183102049187506032",
"268387595942067166965926131962911238158",
"251864851443250010333070596045517806039",
"77139260241216743985620092091127670485",
"217428350190090981022896446737746675007",
"154220734962593317291892671209024157273",
"255066945339245079419294192694320204113",
"184734217222970944327959224278876882049",
"150524077735285677048918570159443093951",
"287458558688669801764240494434728705245",
"137898569842873787913950811566316947724",
"88937017370909443889470675460931461494",
"225404232148617784443053188936048544119"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"target": {
"file": "server/src/test/java/org/elasticsearch/action/admin/cluster/migration/TransportGetFeatureUpgradeStatusActionTests.java",
"function": "testGetFeatureStatus"
},
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/2d58d0f136141f03239816a4e360a8d17b6d8f29",
"id": "CVE-2022-38779-a6f12d5b",
"signature_version": "v1",
"digest": {
"function_hash": "320088857579918567607363477088866754164",
"length": 377.0
}
},
{
"signature_type": "Line",
"target": {
"file": "test/test-clusters/src/main/java/org/elasticsearch/test/cluster/local/LocalClusterFactory.java"
},
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/ef48222227ee6b9e70e502f0f0daa52435ee634d",
"id": "CVE-2022-38779-adc0c667",
"signature_version": "v1",
"digest": {
"line_hashes": [
"328783117535713225377078719017895934894",
"218962949926834068220532377964025986269",
"238873534878858557428085250597699491727",
"63077107520883219164804643621703692733",
"66788853691360615475714774552204583495",
"235984818079188790404255208318579500458",
"122272605970820100222461377080912574433",
"218240151183537112180691515958244680759",
"74982244718916453758071782997683156102",
"338998086836341997413146815199410074826",
"183545008697450786058075772372139794156",
"14150877025559646740082274151309028560",
"165346515570815984485986167003908280712",
"133921416539802914293419784636618607124",
"335194391246084399905387481005122256392",
"287472674007991101034770761473652905017",
"32088835855662654741678314163880302816",
"1737611290573491832151774625136018650",
"41302012581605084517150417062557235387",
"111850715464812135337423374498156388695",
"190938082947915130398453485194117962279",
"200222680760379930174317775945798073524"
],
"threshold": 0.9
}
},
{
"signature_type": "Line",
"target": {
"file": "modules/reindex/src/internalClusterTest/java/org/elasticsearch/migration/AbstractFeatureMigrationIntegTest.java"
},
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/2d58d0f136141f03239816a4e360a8d17b6d8f29",
"id": "CVE-2022-38779-b559d63c",
"signature_version": "v1",
"digest": {
"line_hashes": [
"248047417370916315439752865592395175956",
"315983797586265415583834353066933331736",
"312013460032099731481871450009937804796",
"143767621828807655676638691579891705261",
"136448671909715594618604443327799286145",
"330588128067386814695626037070539070387",
"255437223768996420483918861391573387200",
"228797384174437050426060611486730326156",
"179948730281860460728605003216012652508",
"146910777192892687368175157311193383978",
"252180710832146766022433591571011194129"
],
"threshold": 0.9
}
},
{
"signature_type": "Line",
"target": {
"file": "server/src/main/java/org/elasticsearch/action/admin/cluster/migration/TransportGetFeatureUpgradeStatusAction.java"
},
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/2d58d0f136141f03239816a4e360a8d17b6d8f29",
"id": "CVE-2022-38779-bc84fa57",
"signature_version": "v1",
"digest": {
"line_hashes": [
"258489881906712820950852082223712412471",
"224427820974090640552193107358110666765",
"116392234902123390529359812958365300789",
"154801713849791830830675898279228738538",
"90972928435560328054350297142577549930",
"229580121594427613184356826595104767736",
"197909314958452003170714354142190779122",
"131167841232331831811428081488851824861"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"target": {
"file": "server/src/test/java/org/elasticsearch/action/admin/cluster/migration/TransportGetFeatureUpgradeStatusActionTests.java",
"function": "getClusterState"
},
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/2d58d0f136141f03239816a4e360a8d17b6d8f29",
"id": "CVE-2022-38779-eed8a9d9",
"signature_version": "v1",
"digest": {
"function_hash": "19156491380485715914822349670737399228",
"length": 671.0
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-38779.json"