Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-38779

Опубликовано: 08 фев. 2023
Источник: redhat
CVSS3: 6.1

Описание

An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.

An open redirect flaw was found in Kibana. This issue can lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-rhel8-operatorAffected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-rhel8-operatorAffected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Not affected
Red Hat JBoss Fuse 6kibanaOut of support scope
Red Hat JBoss Fuse Service Works 6kibanaOut of support scope
Red Hat OpenShift Container Platform 3.11kibanaOut of support scope
Red Hat OpenShift Container Platform 3.11openshift3/ose-logging-kibana5Out of support scope
Red Hat OpenStack Platform 13 (Queens)puppet-kibana3Out of support scope
Red Hat OpenStack Platform 16.1puppet-kibana3Will not fix
Red Hat OpenStack Platform 16.2puppet-kibana3Will not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=2172352kibana: Kibana open redirect issue (ESA-2023-03)

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
почти 3 года назад

An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.

CVSS3: 6.1
debian
почти 3 года назад

An open redirect issue was discovered in Kibana that could lead to a u ...

CVSS3: 6.1
github
почти 3 года назад

An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.

6.1 Medium

CVSS3