The floragunn Search Guard plugin before 6.x-16 for Kibana allows URL injection for login redirects on the login page when basePath is set.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://docs.search-guard.com/latest/changelog-kibana-6.x-16 | patch vendor advisory |
https://github.com/floragunncom/search-guard-kibana-plugin/pull/140 | third party advisory |