Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating PDF reports. If a report requests external resources plaintext credentials are included in the HTTP request that could be recovered by an external resource provider.
2018-12-20T22:29:00.303
2024-11-21T03:54:09.150
Modified
CVSSv3.0: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | elastic | kibana | ≤ 4.6.0 | Yes |
Application | elastic | kibana | ≤ 5.6.12 | Yes |
Application | elastic | kibana | ≤ 6.4.2 | Yes |