Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-17245

Опубликовано: 20 дек. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 5
EPSS Низкий

Описание

Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating PDF reports. If a report requests external resources plaintext credentials are included in the HTTP request that could be recovered by an external resource provider.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
Версия от 4.0.0 (включая) до 4.6.0 (включая)
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
Версия от 5.0.0 (включая) до 5.6.12 (включая)
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
Версия от 6.0.0 (включая) до 6.4.2 (включая)

EPSS

Процентиль: 55%
0.00322
Низкий

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-201
CWE-522

Связанные уязвимости

CVSS3: 7.5
redhat
больше 7 лет назад

Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating PDF reports. If a report requests external resources plaintext credentials are included in the HTTP request that could be recovered by an external resource provider.

CVSS3: 9.8
debian
около 7 лет назад

Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an ...

CVSS3: 9.8
github
больше 3 лет назад

Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating PDF reports. If a report requests external resources plaintext credentials are included in the HTTP request that could be recovered by an external resource provider.

EPSS

Процентиль: 55%
0.00322
Низкий

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-201
CWE-522