Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-11482

Опубликовано: 17 дек. 2017
Источник: redhat
CVSS3: 6.1

Описание

The Kibana fix for CVE-2017-8451 was found to be incomplete. With X-Pack installed, Kibana versions before 6.0.1 and 5.6.5 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational ToolskibanaNot affected
Red Hat JBoss Fuse 6hawtio-kibanaNot affected
Red Hat OpenShift Enterprise 3kibanaWill not fix
Red Hat OpenStack Platform 10 (Newton)puppet-kibana3Not affected
Red Hat OpenStack Platform 11 (Ocata)puppet-kibana3Not affected
Red Hat OpenStack Platform 12 (Pike)puppet-kibana3Not affected
Red Hat OpenStack Platform 8 (Liberty) Operational ToolskibanaNot affected
Red Hat OpenStack Platform 9 (Mitaka) Operational ToolskibanaNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=1538796kibana: open redirect on the login page (ESA-2017-23)

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
почти 8 лет назад

The Kibana fix for CVE-2017-8451 was found to be incomplete. With X-Pack installed, Kibana versions before 6.0.1 and 5.6.5 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.

CVSS3: 6.1
debian
почти 8 лет назад

The Kibana fix for CVE-2017-8451 was found to be incomplete. With X-Pa ...

CVSS3: 6.1
github
больше 3 лет назад

The Kibana fix for CVE-2017-8451 was found to be incomplete. With X-Pack installed, Kibana versions before 6.0.1 and 5.6.5 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.

6.1 Medium

CVSS3