Elastic Kibana vulnerabilities

108 known vulnerabilities affecting elastic/kibana.

Total CVEs
108
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH23MEDIUM76LOW2

Vulnerabilities

Page 6 of 6
CVE-2016-1000220MEDIUMCVSS 6.1≥ 4.1.0, < 4.1.11≥ 4.5.0, < 4.5.42017-06-16
CVE-2016-1000220 [MEDIUM] CWE-79 CVE-2016-1000220: Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execu Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScript in users' browsers.
nvd
CVE-2016-10364MEDIUMCVSS 6.5v5.0.0v5.0.12017-06-16
CVE-2016-10364 [MEDIUM] CWE-306 CVE-2016-10364: With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any authenticated user could make requests to those services regardless of their own permissions.
nvd
CVE-2016-10365MEDIUMCVSS 6.1≤ 4.6.2≤ 5.0.0+1 more2017-06-16
CVE-2016-10365 [MEDIUM] CWE-601 CVE-2016-10365: Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an atta Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link in the Kibana domain that redirects to an arbitrary website.
cvelistv5nvd
CVE-2015-9056MEDIUMCVSS 6.1≥ 4.1.0, < 4.1.3≥ 4.2.0, < 4.2.1+2 more2017-06-16
CVE-2015-9056 [MEDIUM] CWE-79 CVE-2015-9056: Kibana versions prior to 4.1.3 and 4.2.1 are vulnerable to a XSS attack. Kibana versions prior to 4.1.3 and 4.2.1 are vulnerable to a XSS attack.
cvelistv5nvd
CVE-2017-8440MEDIUMCVSS 6.1v5.3.0v5.3.1+4 more2017-06-05
CVE-2017-8440 [MEDIUM] CWE-79 CVE-2017-8440: Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover pag Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
cvelistv5nvd
CVE-2017-8439MEDIUMCVSS 6.1v5.4.02017-06-05
CVE-2017-8439 [MEDIUM] CWE-79 CVE-2017-8439: Kibana version 5.4.0 was affected by a Cross Site Scripting (XSS) bug in the Time Series Visual Buil Kibana version 5.4.0 was affected by a Cross Site Scripting (XSS) bug in the Time Series Visual Builder. This bug could allow an attacker to obtain sensitive information from Kibana users.
cvelistv5nvd
CVE-2015-8131MEDIUMCVSS 6.8≤ 4.1.2v4.2.02015-12-07
CVE-2015-8131 [MEDIUM] CWE-352 CVE-2015-8131: Cross-site request forgery (CSRF) vulnerability in Elasticsearch Kibana before 4.1.3 and 4.2.x befor Cross-site request forgery (CSRF) vulnerability in Elasticsearch Kibana before 4.1.3 and 4.2.x before 4.2.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
nvd
CVE-2015-4093MEDIUMCVSS 4.3v4.0.0v4.0.1+1 more2015-06-15
CVE-2015-4093 [MEDIUM] CWE-79 CVE-2015-4093: Cross-site scripting (XSS) vulnerability in Elasticsearch Kibana 4.x before 4.0.3 allows remote atta Cross-site scripting (XSS) vulnerability in Elasticsearch Kibana 4.x before 4.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd