An open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously crafted URL, it could result in Kibana redirecting the user to an arbitrary website.
2022-11-18T23:15:11.553
2025-04-29T20:15:18.230
Modified
CVSSv3.1: 6.1 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | elastic | kibana | < 6.8.16 | Yes |
Application | elastic | kibana | < 7.13.0 | Yes |