Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-22141

Опубликовано: 25 мая 2021
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

An open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously crafted URL, it could result in Kibana redirecting the user to an arbitrary website.

An open redirect flaw was found in Kibana. An attacker is able to redirect a logged Kibana user to an arbitrary website by specially crafted URL.

Отчет

OpenShift Container Platform (OCP) 4 delivered the kibana package but during the update to container first (openshift4/ose-logging-kibana6 since OCP 4.5) the kibana package is not maintained anymore, hence is marked as wontfix.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Fix deferred
Red Hat OpenShift Container Platform 3.11kibanaFix deferred
Red Hat OpenShift Container Platform 4kibanaWill not fix
Red Hat OpenShift Container Platform 4openshift4/ose-logging-kibana6Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-601

EPSS

Процентиль: 47%
0.00239
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
около 3 лет назад

An open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously crafted URL, it could result in Kibana redirecting the user to an arbitrary website.

CVSS3: 6.1
debian
около 3 лет назад

An open redirect flaw was found in Kibana versions before 7.13.0 and 6 ...

CVSS3: 6.1
github
около 3 лет назад

An open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously crafted URL, it could result in Kibana redirecting the user to an arbitrary website.

EPSS

Процентиль: 47%
0.00239
Низкий

4.3 Medium

CVSS3